PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-66395 siyuan-note CVE debrief

CVE-2026-66395 is a reflected cross-site scripting vulnerability in the bazaar plugin readme handler of SiYuan desktop before v3.7.2. This vulnerability allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. The vulnerability is caused by the insecure configuration of the Electron renderer, which allows attackers to inject HTML payloads via the plugin name parameter that execute with full Node.js access through insertAdjacentHTML rendering. The CVSS score for this vulnerability is 9.4, indicating a critical severity. Users of SiYuan desktop before v3.7.2 should apply the patch to prevent exploitation of this vulnerability. Additionally, users should be cautious when clicking on links from untrusted sources, as they may be used to exploit this vulnerability.

Vendor
siyuan-note
Product
siyuan
CVSS
CRITICAL 9.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-27
Original CVE updated
2026-07-27
Advisory published
2026-07-27
Advisory updated
2026-07-27

Who should care

Users of SiYuan desktop before v3.7.2 should apply the patch to prevent exploitation of this vulnerability. Additionally, users should be cautious when clicking on links from untrusted sources, as they may be used to exploit this vulnerability. Operators of SiYuan desktop instances should review compensating controls for exposed systems while remediation is scheduled and verified. Security teams should monitor for suspicious activity on SiYuan desktop instances.

Technical summary

The vulnerability is a reflected cross-site scripting (XSS) vulnerability in the bazaar plugin readme handler of SiYuan desktop before v3.7.2. The vulnerability allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. The vulnerability is caused by the insecure configuration of the Electron renderer, which allows attackers to inject HTML payloads via the plugin name parameter that execute with full Node.js access through insertAdjacentHTML rendering. The CVSS score for this vulnerability is 9.4, indicating a critical severity.

Defensive priority

High

Recommended defensive actions

  • Apply the patch to upgrade SiYuan desktop to v3.7.2 or later
  • Be cautious when clicking on links from untrusted sources
  • Monitor for suspicious activity on SiYuan desktop instances
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record was published on 2026-07-27T16:18:12.083Z and has not been modified since then. The NVD entry is currently 9.4. The vulnerability is a reflected cross-site scripting (XSS) vulnerability in the bazaar plugin readme handler of SiYuan desktop before v3.7.2. The vulnerability allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. The vulnerability is caused by the insecure configuration of the Electron renderer, which allows attackers to inject HTML payloads via the plugin name parameter that execute with full Node.js access through insertAdjacentHTML rendering. Evidence limits suggest that defenders verify patch application and monitor for suspicious activity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T16:18:12.083Z and has not been modified since then. The NVD entry is currently 9.4.