
CVE-2026-25647 Lute is a structured Markdown engine supporting Go and JavaScript. Lute 1.7.6 and earlier (as used in SiYuan before) has a Stored Cross-Site Scripting (XSS) vulnerabi… https://www.cve.org/CVERecord?id=CVE-2026-25647
Post summary
The passage announces a stored XSS vulnerability (CVE‑2026‑25647) in Lute 1.7.6 and earlier, used in SiYuan, but provides no PoC, exploit, or patch details.
