{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/siyuan--3.8.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:siyuan:siyuan:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-92985"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SiYuan (\u003c 3.8.4)","SiYuan (\u003c 3.8.3)","SiYuan (\u003c= 3.8.4)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","electron","xss","web-application-vulnerability","sql-injection","data-exfiltration","web-vulnerability","remote-code-execution"],"_cs_type":"advisory","_cs_vendors":["SiYuan"],"content_html":"\u003cp\u003eSiYuan versions prior to 3.8.4 contain a critical vulnerability that allows attackers to achieve remote code execution (RCE). The application fails to properly sanitize or escape bookmark labels when importing and rendering .sy notebook files within the dock tree. Because the underlying Electron framework is configured with nodeIntegration enabled, the rendering of malicious HTML payloads within these bookmark attributes allows for the execution of arbitrary JavaScript. This execution occurs within the context of the renderer process, granting the attacker access to Node.js primitives, including the child_process module, which can be leveraged to execute arbitrary system commands on the host machine. This affects all platforms where SiYuan is deployed, as it relies on the Electron-based architecture.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to execute arbitrary commands with the privileges of the user running the SiYuan application. This can lead to full system compromise, data exfiltration, or the installation of persistent backdoors. The vulnerability is highly severe because it does not require complex infrastructure, only the victim's interaction with a malicious .sy file.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all SiYuan installations to version 3.8.4 or later immediately.\u003c/li\u003e\n\u003cli\u003eRestrict the import of untrusted or externally sourced .sy notebook files until patches are applied.\u003c/li\u003e\n\u003cli\u003eReview endpoint telemetry for suspicious process execution patterns originating from the SiYuan process tree.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-19T02:07:36Z","date_published":"2026-09-17T16:00:22Z","id":"https://feed.craftedsignal.io/briefs/2026-09-siyuan-xss-rce/","summary":"SiYuan versions prior to 3.8.4 contain a cross-site scripting vulnerability in bookmark label rendering that enables remote code execution due to insecure Electron configuration.","title":"Remote Code Execution in SiYuan via Malicious Bookmark Labels","url":"https://feed.craftedsignal.io/briefs/2026-09-siyuan-xss-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - SiYuan (\u003c= 3.8.4)","version":"https://jsonfeed.org/version/1.1"}