
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34448 is a stored Cross-Site Scripting (XSS) vulnerability in SiYuan, a personal knowledge management system, that escalates to arbitrary OS command execution in the Electron desktop client. An attacker with low-privileged write access to an Attribute View mAsset field can inject a malicious URL that, when rendered in Gallery or Kanban view with "Cover From -> Asset Field" enabled, executes arbitrary JavaScript with full Node.js API access. All versions up to and including 3.6.1 are affected; the issue was patched in version 3.6.2, released March 31, 2026. It carries a CVSS v3.1 base score of 9.0 (Critical) (Github Advisory, SiYuan Advisory).
The root cause is improper neutralization of user-controlled input (CWE-79) combined with code injection (CWE-94). The vulnerable function IsPossiblyImage(assetPath) accepts arbitrary http(s) URLs without validating they point to safe image resources; the application then copies asset.Content directly into galleryCard.CoverURL / kanbanCard.CoverURL and the front-end renderer inserts this value into an <img src="..."> attribute without escaping quotes or other attribute-breaking characters. A payload such as https://example.com/" onerror="require('child_process').exec('calc') breaks out of the src attribute and injects an attacker-controlled onerror handler. Because the SiYuan Electron desktop client is configured with nodeIntegration: true, contextIsolation: false, and webSecurity: false, the injected JavaScript executes with full Node.js API access, enabling arbitrary OS command execution (Github Advisory, SiYuan Advisory).
Successful exploitation grants an attacker arbitrary OS command execution under the victim's local user account, escalating what begins as a stored XSS into full remote code execution on the desktop client. All three security pillars are critically affected: confidentiality (access to local files and secrets), integrity (ability to modify or delete data), and availability (ability to disrupt the system). Because the payload is stored persistently in the database, any user who opens the affected Gallery or Kanban view is automatically compromised without further attacker interaction beyond the initial write (Github Advisory).
A detailed proof-of-concept (PoC) with eight numbered reproduction steps and a specific payload is publicly documented in the GitHub Security Advisory, confirmed as a real exploit by Feedly threat intelligence (SiYuan Advisory). The EPSS score is approximately 0.049% (low probability of near-term mass exploitation), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing (Github Advisory). Exploitation requires low privileges (write access to an Attribute View) and user interaction (victim must open the Gallery or Kanban view), but no special configuration beyond the default Electron desktop client setup.
mAsset (multi-asset) column with at least one existing row.image, satisfying the IsPossiblyImage check.https://example.com/" onerror="require('child_process').exec('calc')coverURL.coverURL into <img src="...">, producing <img src="https://example.com/" onerror="require('child_process').exec('calc')">.onerror handler. Because nodeIntegration: true and contextIsolation: false are set in the Electron client, require('child_process').exec('calc') runs with the victim's OS privileges, launching the Calculator (or any other command) (SiYuan Advisory).calc.exe, cmd.exe, bash, sh, powershell.exe, curl, wget) visible in process trees.onerror attributes or unusual URL patterns in coverURL fields (e.g., URLs containing onerror, require, child_process).", ') or JavaScript keywords (onerror, require, exec, child_process).siyuan.exe or equivalent) spawns system shells or utilities not typical of normal application behavior (SiYuan Advisory).The primary remediation is to upgrade SiYuan to version 3.6.2 or later, which patches this vulnerability along with several other security issues (SiYuan Release). For users who cannot immediately upgrade, consider restricting write access to Attribute View databases to trusted users only, and disabling or avoiding the "Cover From -> Asset Field" feature in Gallery and Kanban views until patching is complete (Github Advisory). Review existing mAsset field entries for suspicious URLs containing HTML special characters or JavaScript keywords as a precautionary measure.
The vulnerability was covered by The Hacker Wire, which published a dedicated article on the stored XSS-to-RCE chain (The Hacker Wire). Security researcher ngocnn97 was credited as the reporter in the official GitHub Security Advisory (Github Advisory). Discussion was noted on Mastodon and Bluesky social platforms, and the vulnerability was also covered by yazoul.net in a dedicated advisory (Yazoul Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."