{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/electron-app/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.6,"id":"CVE-2026-66395"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SiYuan Desktop (\u003c 3.7.2)"],"_cs_severities":["critical"],"_cs_tags":["reflected-xss","rce","electron-app"],"_cs_type":"advisory","_cs_vendors":["SiYuan-Note"],"content_html":"\u003cp\u003eCVE-2026-66395 details a critical reflected cross-site scripting (XSS) vulnerability impacting SiYuan desktop versions prior to 3.7.2. This flaw, residing in the bazaar plugin readme handler, enables an attacker to achieve Remote Code Execution (RCE). The attack vector involves crafting a malicious \u003ccode\u003esiyuan://\u003c/code\u003e deep link that embeds an HTML payload within the \u003ccode\u003eplugin name\u003c/code\u003e parameter. When a user is persuaded to open this link, the SiYuan application, built on Electron, processes the URL. Due to an insecure configuration of its Electron renderer, the malicious HTML is rendered via \u003ccode\u003einsertAdjacentHTML\u003c/code\u003e, granting the attacker full Node.js access and the ability to execute arbitrary code on the victim's system. This vulnerability poses a significant threat, as it can lead to complete system compromise if exploited.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker crafts a malicious \u003ccode\u003esiyuan://\u003c/code\u003e deep link, embedding an XSS payload within the \u003ccode\u003eplugin name\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eThe crafted deep link is delivered to a victim, typically via social engineering tactics such as email or chat messages.\u003c/li\u003e\n\u003cli\u003eThe victim is enticed to click or open the malicious deep link.\u003c/li\u003e\n\u003cli\u003eThe operating system's deep link handler invokes the installed SiYuan desktop application to process the \u003ccode\u003esiyuan://\u003c/code\u003e URL.\u003c/li\u003e\n\u003cli\u003eThe SiYuan application processes the URL, passing the malicious \u003ccode\u003eplugin name\u003c/code\u003e parameter to the bazaar plugin readme handler.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ereadme\u003c/code\u003e handler renders the crafted HTML payload using \u003ccode\u003einsertAdjacentHTML\u003c/code\u003e within an insecurely configured Electron renderer process.\u003c/li\u003e\n\u003cli\u003eThe embedded JavaScript within the HTML payload executes with full Node.js privileges, allowing the attacker to run arbitrary code on the victim's system.\u003c/li\u003e\n\u003cli\u003eThis results in Remote Code Execution (RCE), enabling further compromise such as data exfiltration, installation of malware, or establishing persistence.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-66395 grants an attacker Remote Code Execution (RCE) capabilities on the victim's system. This can lead to severe consequences, including full control over the compromised machine, sensitive data theft, privilege escalation, and deployment of additional malicious payloads like ransomware or backdoors. While specific victim counts or targeted sectors are not detailed in the source, any user of SiYuan desktop applications running a vulnerable version is at risk, across all operating systems where the application is deployed (Windows, Linux, macOS). The high CVSS score of 9.6 reflects the critical nature of this vulnerability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-66395 immediately by updating SiYuan desktop to version 3.7.2 or later on all affected Windows, Linux, and macOS systems.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule \u0026quot;Detect Suspicious Child Process from SiYuan Desktop\u0026quot; to your SIEM and tune for your environment to identify potential RCE attempts originating from the SiYuan application.\u003c/li\u003e\n\u003cli\u003eMonitor process creation events for \u003ccode\u003eSiYuan.exe\u003c/code\u003e (or \u003ccode\u003esiyuan\u003c/code\u003e on Linux/macOS) spawning unusual child processes such as command shells or scripting interpreters, as outlined in the Sigma rule.\u003c/li\u003e\n\u003cli\u003eEducate users about the dangers of opening deep links from untrusted or suspicious sources, especially those that appear to invoke \u003ccode\u003esiyuan://\u003c/code\u003e protocol.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-27T16:27:06Z","date_published":"2026-07-27T16:27:06Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-66395-siyuan-rce/","summary":"A reflected cross-site scripting (XSS) vulnerability exists in SiYuan desktop applications before version 3.7.2, specifically within the bazaar plugin readme handler, allowing attackers to execute arbitrary code by crafting a malicious 'siyuan://' deep link, which leads to Remote Code Execution (RCE) with full Node.js access due to insecure Electron renderer configuration.","title":"CVE-2026-66395 - SiYuan Desktop Reflected XSS to RCE","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-66395-siyuan-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Electron-App","version":"https://jsonfeed.org/version/1.1"}