<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>SiYuan (&lt; 3.8.3) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/siyuan--3.8.3/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 17 Sep 2026 16:00:22 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/siyuan--3.8.3/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution in SiYuan via Malicious Bookmark Labels</title><link>https://feed.craftedsignal.io/briefs/2026-09-siyuan-xss-rce/</link><pubDate>Thu, 17 Sep 2026 16:00:22 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-siyuan-xss-rce/</guid><description>SiYuan versions prior to 3.8.4 contain a cross-site scripting vulnerability in bookmark label rendering that enables remote code execution due to insecure Electron configuration.</description><content:encoded><![CDATA[<p>SiYuan versions prior to 3.8.4 contain a critical vulnerability that allows attackers to achieve remote code execution (RCE). The application fails to properly sanitize or escape bookmark labels when importing and rendering .sy notebook files within the dock tree. Because the underlying Electron framework is configured with nodeIntegration enabled, the rendering of malicious HTML payloads within these bookmark attributes allows for the execution of arbitrary JavaScript. This execution occurs within the context of the renderer process, granting the attacker access to Node.js primitives, including the child_process module, which can be leveraged to execute arbitrary system commands on the host machine. This affects all platforms where SiYuan is deployed, as it relies on the Electron-based architecture.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an unauthenticated attacker to execute arbitrary commands with the privileges of the user running the SiYuan application. This can lead to full system compromise, data exfiltration, or the installation of persistent backdoors. The vulnerability is highly severe because it does not require complex infrastructure, only the victim's interaction with a malicious .sy file.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all SiYuan installations to version 3.8.4 or later immediately.</li>
<li>Restrict the import of untrusted or externally sourced .sy notebook files until patches are applied.</li>
<li>Review endpoint telemetry for suspicious process execution patterns originating from the SiYuan process tree.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>rce</category><category>electron</category><category>xss</category><category>web-application-vulnerability</category><category>sql-injection</category><category>data-exfiltration</category><category>web-vulnerability</category><category>remote-code-execution</category></item></channel></rss>