
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34585 is a stored XSS vulnerability in SiYuan, a personal knowledge management system, that escalates to arbitrary command execution (RCE) in the Electron desktop client. The flaw affects all SiYuan versions prior to 3.6.2 (Go module github.com/siyuan-note/siyuan/kernel). It was reported by researcher ngocnn97, published to the GitHub Advisory Database on April 1, 2026, and patched in v3.6.2 released March 31, 2026. The vulnerability carries a CVSS v3.1 base score of 8.6 (High) (Github Advisory, SiYuan Advisory).
The root cause is a logic regression in the escapeNodeAttributeValues function within kernel/filesys/tree.go (CWE-79, CWE-94). The updated needsEscapeForValue implementation inspects raw KramdownIAL values directly and returns false (no escaping needed) as soon as it encounters a known HTML entity such as &, ", <, or >. This means a crafted value mixing an HTML entity with an unescaped raw quote — for example, &" onmouseenter="require('child_process').exec('calc') — bypasses escaping entirely. The renderer then inserts these block IAL values directly into HTML attributes, creating a stored XSS condition; in the Electron desktop client, the injected JavaScript executes with full Node.js/Electron API access, enabling arbitrary OS command execution (Github Advisory, SiYuan Advisory).
Successful exploitation allows an attacker to achieve full remote code execution on the victim's machine under their user account. In the SiYuan Electron desktop client, injected JavaScript runs with Node.js integration enabled, granting access to Node/Electron APIs and the ability to execute arbitrary OS commands (e.g., launching calc.exe on Windows as a proof of concept). The confidentiality, integrity, and availability impacts are all rated High, as an attacker can read sensitive data, modify files, and disrupt system operation — all without requiring elevated privileges (Github Advisory).
A detailed proof-of-concept (PoC) with a nine-step reproduction procedure is publicly available in the GitHub Security Advisory, including the specific malicious payload and the crafted .sy.zip structure needed to trigger RCE (SiYuan Advisory). Exploitation requires user interaction — the victim must import the malicious archive and open the note, then hover over the affected block — but no privileges are required of the attacker. The EPSS score is approximately 0.091% (26th percentile), and there is no evidence of in-the-wild exploitation or CISA KEV catalog listing at this time (Github Advisory).
.sy document file containing a block with a crafted IAL (Inline Attribute List) property, such as:"title": "&\" onmouseenter=\"require('child_process').exec('calc')".sy document into a .sy.zip archive using standard zip tooling..sy.zip to the target victim via email, file sharing, or any social engineering channel.onmouseenter event handler.calc.exe launches on Windows, demonstrating arbitrary command execution under the victim's account) (SiYuan Advisory)..sy.zip files in the user's downloads or temp directories; newly imported SiYuan notebooks with unusual block attribute values containing HTML entities mixed with event handler strings (e.g., onmouseenter, onerror).calc.exe, cmd.exe, powershell.exe on Windows; bash, sh, python on Linux/macOS); unusual network connections initiated by SiYuan's renderer process..sy.zip files from untrusted paths; Electron/Chromium renderer logs indicating JavaScript execution errors or Node.js API calls from within note content.The vulnerability is patched in SiYuan v3.6.2, released March 31, 2026, which fixes the escapeNodeAttributeValues logic regression in kernel/filesys/tree.go. Users should upgrade to v3.6.2 or later immediately (SiYuan Release). As a workaround until patching is possible, users should avoid importing .sy.zip files from untrusted or unknown sources, as the attack vector requires the victim to import a malicious archive (Github Advisory).
The vulnerability was discussed on Bluesky and Mastodon/infosec.exchange shortly after disclosure, with community members noting the severity of the XSS-to-RCE escalation path in an Electron application. Coverage appeared on The Hacker Wire and yazoul.net, highlighting the import-based attack vector. No major vendor statements beyond the official GitHub Security Advisory have been identified (Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."