PatchSiren cyber security CVE debrief
CVE-2026-66395 siyuan-note CVE debrief
CVE-2026-66395 is a reflected cross-site scripting vulnerability in the bazaar plugin readme handler of SiYuan desktop before v3.7.2. This vulnerability allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. The vulnerability is caused by the insecure configuration of the Electron renderer, which allows attackers to inject HTML payloads via the plugin name parameter that execute with full Node.js access through insertAdjacentHTML rendering. The CVSS score for this vulnerability is 9.4, indicating a critical severity. Users of SiYuan desktop before v3.7.2 should apply the patch to prevent exploitation of this vulnerability. Additionally, users should be cautious when clicking on links from untrusted sources, as they may be used to exploit this vulnerability.
- Vendor
- siyuan-note
- Product
- siyuan
- CVSS
- CRITICAL 9.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-27
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-27
- Advisory updated
- 2026-07-27
Who should care
Users of SiYuan desktop before v3.7.2 should apply the patch to prevent exploitation of this vulnerability. Additionally, users should be cautious when clicking on links from untrusted sources, as they may be used to exploit this vulnerability. Operators of SiYuan desktop instances should review compensating controls for exposed systems while remediation is scheduled and verified. Security teams should monitor for suspicious activity on SiYuan desktop instances.
Technical summary
The vulnerability is a reflected cross-site scripting (XSS) vulnerability in the bazaar plugin readme handler of SiYuan desktop before v3.7.2. The vulnerability allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. The vulnerability is caused by the insecure configuration of the Electron renderer, which allows attackers to inject HTML payloads via the plugin name parameter that execute with full Node.js access through insertAdjacentHTML rendering. The CVSS score for this vulnerability is 9.4, indicating a critical severity.
Defensive priority
High
Recommended defensive actions
- Apply the patch to upgrade SiYuan desktop to v3.7.2 or later
- Be cautious when clicking on links from untrusted sources
- Monitor for suspicious activity on SiYuan desktop instances
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-07-27T16:18:12.083Z and has not been modified since then. The NVD entry is currently 9.4. The vulnerability is a reflected cross-site scripting (XSS) vulnerability in the bazaar plugin readme handler of SiYuan desktop before v3.7.2. The vulnerability allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. The vulnerability is caused by the insecure configuration of the Electron renderer, which allows attackers to inject HTML payloads via the plugin name parameter that execute with full Node.js access through insertAdjacentHTML rendering. Evidence limits suggest that defenders verify patch application and monitor for suspicious activity.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T16:18:12.083Z and has not been modified since then. The NVD entry is currently 9.4.