SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock tree. Attackers can craft malicious .sy notebook files with unescaped HTML in bookmark attributes that execute scripts in the Electron renderer with access to child_process for command execution.
https://www.vulncheck.com/advisories/siyuan-before-3.8.4-cross-site-scripting-via-bookmark-labels
https://github.com/siyuan-note/siyuan/security/advisories/GHSA-jhfc-9mcq-8p8v
https://github.com/siyuan-note/siyuan/commit/6f093ebe50afc503e2a8b056164293054f8509e7
https://github.com/siyuan-note/siyuan/blob/v3.8.3/app/src/util/Tree.ts#L134
Published: 2026-09-17
Updated: 2026-09-17
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 8.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity: High
Base Score: 8.6
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity: High
EPSS: 0.00518