Product
A stored cross-site scripting (XSS) vulnerability, identified as CVE-2026-65605, exists in SiYuan prior to version v3.7.2. The flaw allows an attacker to inject crafted HTML, such as an `<img>` tag with an `onerror` attribute, which, when viewed in the Attribute View (database) cell rendering, executes arbitrary JavaScript and can escalate to remote code execution due to `nodeIntegration` being enabled in the desktop renderer.