PatchSiren cyber security CVE debrief
CVE-2026-75917 siyuan-note CVE debrief
A critical vulnerability exists in SiYuan versions before v3.7.4, allowing for cross-site scripting (XSS) to remote code execution (RCE) via the pathName.ts file. This vulnerability is triggered through the file-tree picker's hover-tooltip generation used by 'move/link to' path-selection dialogs. An attacker can craft a malicious document with a double quote in specific metadata fields, which, when hovered over in the path-picker dialog, injects arbitrary HTML attributes and inline event handlers. Due to the Electron BrowserWindow configuration (nodeIntegration:true, contextIsolation:false, and no CSP), the injected handler can escalate the XSS to arbitrary OS command execution.
- Vendor
- siyuan-note
- Product
- siyuan
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-10-08
Who should care
Users of SiYuan versions before v3.7.4 should assess their exposure and take necessary actions to update or mitigate the vulnerability. This includes administrators and users who utilize SiYuan for note-taking and collaboration.
Why it matters
CVE-2026-75917 is a critical vulnerability in SiYuan before v3.7.4, allowing for XSS-to-RCE escalation. Users and administrators should prioritize updating to v3.7.4 or later and assess their exposure to mitigate potential risks.
- Potential for arbitrary OS command execution
- Elevation of privileges through XSS escalation
- Risk of malicious document exploitation through sharing, sync, or import
- Need for verification of affected versions and configurations
Technical summary
The vulnerability exists in the file-tree picker's hover-tooltip generation in SiYuan versions before v3.7.4. The issue arises from the concatenation of document metadata fields into the aria-label HTML attribute without escaping, allowing for XSS. The XSS can be escalated to RCE due to the Electron BrowserWindow configuration. Affected product deployments should be identified in managed environments, and owners should be assigned for follow-up. The CVE record and vendor advisory should be reviewed to validate affected scope, severity, and vendor guidance.
Defensive priority
High priority should be given to updating SiYuan to version v3.7.4 or later. Users should assess their exposure, especially those using versions before v3.7.4, and verify the integrity of their installations.
Recommended defensive actions
- Update SiYuan to version v3.7.4 or later
- Assess exposure and verify installation integrity for versions before v3.7.4
- Implement compensating controls to monitor and restrict access to sensitive data and systems
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The vulnerability details are based on the CVE Program record and the source item from cve_program_cvelist_v5. The affected versions and configurations are specified in the source item. Evidence limits suggest verifying the integrity of SiYuan installations, especially for versions before v3.7.4, and assessing exposure to mitigate potential risks. Defenders should review the CVE record and vendor advisory for accurate affected scope and severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75917 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75917
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75917 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75917
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
SiYuan before v3.7.4 XSS-to-RCE via pathName.ts
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/75xxx/CVE-2026-75917.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-jjq3-3942-x99r
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/siyuan-before-xss-to-rce-via-pathname-ts
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.