CVE-2026-34585: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-34585 is a stored XSS vulnerability in SiYuan, a personal knowledge management system, that escalates to arbitrary command execution (RCE) in the Electron desktop client. The flaw affects all SiYuan versions prior to 3.6.2 (Go module github.com/siyuan-note/siyuan/kernel). It was reported by researcher ngocnn97, published to the GitHub Advisory Database on April 1, 2026, and patched in v3.6.2 released March 31, 2026. The vulnerability carries a CVSS v3.1 base score of 8.6 (High) (Github Advisory, SiYuan Advisory).

Technical details

The root cause is a logic regression in the escapeNodeAttributeValues function within kernel/filesys/tree.go (CWE-79, CWE-94). The updated needsEscapeForValue implementation inspects raw KramdownIAL values directly and returns false (no escaping needed) as soon as it encounters a known HTML entity such as &, ", <, or >. This means a crafted value mixing an HTML entity with an unescaped raw quote — for example, &" onmouseenter="require('child_process').exec('calc') — bypasses escaping entirely. The renderer then inserts these block IAL values directly into HTML attributes, creating a stored XSS condition; in the Electron desktop client, the injected JavaScript executes with full Node.js/Electron API access, enabling arbitrary OS command execution (Github Advisory, SiYuan Advisory).

Impact

Successful exploitation allows an attacker to achieve full remote code execution on the victim's machine under their user account. In the SiYuan Electron desktop client, injected JavaScript runs with Node.js integration enabled, granting access to Node/Electron APIs and the ability to execute arbitrary OS commands (e.g., launching calc.exe on Windows as a proof of concept). The confidentiality, integrity, and availability impacts are all rated High, as an attacker can read sensitive data, modify files, and disrupt system operation — all without requiring elevated privileges (Github Advisory).

Exploitability

A detailed proof-of-concept (PoC) with a nine-step reproduction procedure is publicly available in the GitHub Security Advisory, including the specific malicious payload and the crafted .sy.zip structure needed to trigger RCE (SiYuan Advisory). Exploitation requires user interaction — the victim must import the malicious archive and open the note, then hover over the affected block — but no privileges are required of the attacker. The EPSS score is approximately 0.091% (26th percentile), and there is no evidence of in-the-wild exploitation or CISA KEV catalog listing at this time (Github Advisory).

Exploitation steps

  1. Craft the malicious document: Create a .sy document file containing a block with a crafted IAL (Inline Attribute List) property, such as:
    "title": "&\" onmouseenter=\"require('child_process').exec('calc')"
  2. Package the archive: Compress the malicious .sy document into a .sy.zip archive using standard zip tooling.
  3. Deliver the payload: Distribute the crafted .sy.zip to the target victim via email, file sharing, or any social engineering channel.
  4. Victim imports the archive: The victim opens SiYuan Desktop (v3.6.1 or earlier), right-clicks a notebook, selects Import → SiYuan .sy.zip, and imports the malicious archive.
  5. Victim opens the note: The victim navigates to and opens the imported note in the SiYuan interface.
  6. Trigger execution: The victim moves their mouse over the affected paragraph block, firing the injected onmouseenter event handler.
  7. Achieve RCE: The injected JavaScript executes in the privileged Electron renderer with Node.js API access, running the attacker's OS command (e.g., calc.exe launches on Windows, demonstrating arbitrary command execution under the victim's account) (SiYuan Advisory).

Indicators of compromise

  • File System: Presence of unexpected or externally sourced .sy.zip files in the user's downloads or temp directories; newly imported SiYuan notebooks with unusual block attribute values containing HTML entities mixed with event handler strings (e.g., onmouseenter, onerror).
  • Process: Unexpected child processes spawned by the SiYuan Electron process (e.g., calc.exe, cmd.exe, powershell.exe on Windows; bash, sh, python on Linux/macOS); unusual network connections initiated by SiYuan's renderer process.
  • Logs: SiYuan application logs showing import of .sy.zip files from untrusted paths; Electron/Chromium renderer logs indicating JavaScript execution errors or Node.js API calls from within note content.
  • Network: Outbound connections from the SiYuan process to unexpected external hosts shortly after a note is opened (indicative of a reverse shell or data exfiltration payload) (SiYuan Advisory).

Mitigation and workarounds

The vulnerability is patched in SiYuan v3.6.2, released March 31, 2026, which fixes the escapeNodeAttributeValues logic regression in kernel/filesys/tree.go. Users should upgrade to v3.6.2 or later immediately (SiYuan Release). As a workaround until patching is possible, users should avoid importing .sy.zip files from untrusted or unknown sources, as the attack vector requires the victim to import a malicious archive (Github Advisory).

Community reactions

The vulnerability was discussed on Bluesky and Mastodon/infosec.exchange shortly after disclosure, with community members noting the severity of the XSS-to-RCE escalation path in an Electron application. Coverage appeared on The Hacker Wire and yazoul.net, highlighting the import-based attack vector. No major vendor statements beyond the official GitHub Security Advisory have been identified (Github Advisory).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management