CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-56397: SiYuan 0 to before 3.6.1

CVE-2026-56397. CVSS 3.1 base score 9.6 (CRITICAL, Vendor/CNA). EPSS 0.007 (percentile 0.51626), scored 2026-10-06.

Affected technology

SiYuan · 0 to before 3.6.1
SiYuan

Description’s affected range: before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · Active user interaction

What an attacker can do

Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands. Vendor/CNA’s CVSS 4.0 assessment (base score 9.4/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-79
CCR priority
38.6 /100 (P4)
CVSS 3.1
9.6 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H · Vendor/CNA
EPSS
0.007 · percentile 0.51731 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-56397.html