CVE-2026-87812

high

Description

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in Bazaar package cards where the iconURL metadata is inserted directly into HTML img src attributes without escaping. Attackers can inject malicious URLs with event handlers that execute JavaScript in the authenticated SiYuan origin when users view Bazaar listings, enabling API requests and application state manipulation.

References

https://www.vulncheck.com/advisories/siyuan-before-3.8.2-stored-xss-via-bazaar-iconurl

https://github.com/siyuan-note/siyuan/security/advisories/GHSA-rvcf-q4h8-w6c9

Details

Source: Mitre, NVD

Published: 2026-09-09

Updated: 2026-09-09

Risk Information

CVSS v2

Base Score: 7.1

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:N

Severity: High

CVSS v3

Base Score: 6.8

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

Severity: Medium

CVSS v4

Base Score: 7.4

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.00204