CVE-2026-59855: SiYuan: Store XSS To Rce via Asset.render
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, Asset.render in app/src/asset/index.ts interpolates the unsanitized this.path value into HTML assigned to innerHTML, allowing a crafted asset link containing a double quote to break out of the src attribute, inject an event handler, and execute JavaScript that can run OS commands in the Electron renderer. This issue is fixed in versions 3.7.1-alpha.2 and 3.7.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in 3.7.1-alpha.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59855?
The severity of CVE-2026-59855 is high with a CVSS score of 8.6.
How do I fix CVE-2026-59855?
To fix CVE-2026-59855, upgrade to SiYuan version 3.7.1 or later.
What type of vulnerability is CVE-2026-59855?
CVE-2026-59855 is a cross-site scripting (XSS) vulnerability that can lead to remote code execution.
What is the impact of CVE-2026-59855?
The impact of CVE-2026-59855 allows attackers to execute arbitrary code via crafted asset links.
Which software is affected by CVE-2026-59855?
CVE-2026-59855 affects SiYuan versions prior to 3.7.1.