{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/siyuan--3.7.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.4,"id":"CVE-2026-66396"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SiYuan (\u003c 3.7.2)"],"_cs_severities":["critical"],"_cs_tags":["xss","remote-code-execution","client-side-exploitation","electron"],"_cs_type":"advisory","_cs_vendors":["SiYuan"],"content_html":"\u003cp\u003eCVE-2026-66396 describes a critical vulnerability affecting SiYuan versions prior to v3.7.2, a popular markdown-based note-taking application. The vulnerability stems from improper input neutralization, specifically a stored cross-site scripting (XSS) flaw, where the application fails to escape user-controlled input in the \u003ccode\u003etitle-img Individual Attribute List\u003c/code\u003e value. This occurs during the rendering of Gallery and Kanban cover images. An attacker, requiring existing editor permissions within a SiYuan instance or document, can inject malicious \u003ccode\u003eonload\u003c/code\u003e handlers. When a victim opens an affected document, these handlers execute arbitrary code within the Electron renderer with full Node.js access, effectively enabling remote code execution (RCE) on the victim's system. This flaw poses a significant risk as it can lead to full system compromise from a seemingly benign document interaction.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker obtains editor permissions within a SiYuan instance or document.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious JavaScript payload containing an \u003ccode\u003eonload\u003c/code\u003e handler designed to execute arbitrary commands.\u003c/li\u003e\n\u003cli\u003eThis payload is injected into the \u003ccode\u003etitle-img Individual Attribute List\u003c/code\u003e value of a Gallery or Kanban cover image within a SiYuan document.\u003c/li\u003e\n\u003cli\u003eThe attacker saves the modified document, thereby persisting the malicious payload.\u003c/li\u003e\n\u003cli\u003eA victim user opens the compromised SiYuan document containing the maliciously crafted image.\u003c/li\u003e\n\u003cli\u003eDuring the rendering of the Gallery or Kanban cover image, the SiYuan application fails to properly escape the injected \u003ccode\u003etitle-img Individual Attribute List\u003c/code\u003e value.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eonload\u003c/code\u003e handler embedded in the unescaped value executes, triggering the malicious JavaScript within the Electron renderer process.\u003c/li\u003e\n\u003cli\u003eDue to the Electron application's full Node.js access, the malicious JavaScript achieves arbitrary code execution on the victim's system, leading to remote code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-66396 allows an attacker with editor permissions to achieve remote code execution on the system of any user who opens an affected SiYuan document. This can lead to complete compromise of the victim's workstation, including data exfiltration, installation of additional malware, or further lateral movement within an organization's network. While specific victim numbers are not provided, any organization using vulnerable versions of SiYuan where users share or collaborate on documents is at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-66396 immediately by upgrading SiYuan to version v3.7.2 or later on all affected systems.\u003c/li\u003e\n\u003cli\u003eReview access controls within SiYuan instances to ensure only trusted users have editor permissions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-27T16:23:41Z","date_published":"2026-07-27T16:23:41Z","id":"https://feed.craftedsignal.io/briefs/2026-07-siyuan-xss-rce/","summary":"SiYuan before v3.7.2 is vulnerable to stored cross-site scripting (XSS) due to improper escaping of the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing attackers with editor permissions to inject malicious onload handlers that execute arbitrary code in the Electron renderer with full Node.js access, leading to remote code execution.","title":"SiYuan Stored XSS Leads to Remote Code Execution (CVE-2026-66396)","url":"https://feed.craftedsignal.io/briefs/2026-07-siyuan-xss-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - SiYuan (\u003c 3.7.2)","version":"https://jsonfeed.org/version/1.1"}