CVE-2026-34448Disclosure(b3log / siyuan)

LOWCVSS 9.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch b3log siyuan systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim opens the Gallery or Kanban view with “Cover From -> Asset Field” enabled. The vulnerable code accepts arbitrary http(s) URLs without extensions as images, stores the attacker-controlled string in coverURL, and injects it directly into an <img src="..."> attribute without escaping. In the Electron desktop client, the injected JavaScript executes with nodeIntegration enabled and contextIsolation disabled, so the XSS reaches arbitrary OS command execution under the victim’s account. This issue has been patched in version 3.6.2.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • siyuan

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-01); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
siyuan

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-31: 1Mentions · 2026-04-01: 3Mentions · 2026-04-03: 1PoC Mentioned / Linked · 2026-04-01: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-01: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 3Technical Details · 2026-04-03: 103-3104-0104-03
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-311
Patch1
2026-04-013
Disclosure2Patch1
2026-04-031
Disclosure1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-34448 SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger store… https://www.cve.org/CVERecord?id=CVE-2026-34448

    Post summary

    The text reports a new vulnerability in SiYuan’s Attribute View field that allows malicious URL injection before version 3.6.2, but it does not provide a PoC, exploit code, active exploitation evidence, or a patch.

    0001091
    56.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34448: SiYuan: Stored XSS in Attribute ... Electron's nodeIntegration + contextIsolation disabled turns trivial stored XSS into full RCE - personal knowledge syst... https://zerodaysignal.com/vulnerability/CVE-2026-34448 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-34448, describing a stored XSS in SiYuan that can be escalated to full remote code execution when Electron’s nodeIntegration and contextIsolation are disabled, and provides a link to more details.

    0000047
    197 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `SiYuan` desktop client is affected by a stored XSS (CVE-2026-34448) allowing arbitrary command execution. Mitigation involves cautious content handling until a patch is available. #XSS #InfoSec #CyberSecurity https://www.pulsepatch.io/posts/cve-2026-34448-siyuan-xss-rce

    Post summary

    SiYuan desktop client suffers from a stored XSS (CVE‑2026‑34448) that permits arbitrary command execution; users should handle content cautiously until a vendor patch is released.

    0000031
    6 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-34448 - Critical SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim o... https://www.thehackerwire.com/vulnerability/CVE-2026-34448/ https://t.co/vWMSiC1JE8

    Post summary

    The tweet announces CVE-2026-34448 as a critical stored XSS vulnerability in SiYuan prior to v3.6.2, providing technical details and a link to an article, but no PoC, patch, or active exploitation is detailed.

    0000053
    163 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34448: CRITICAL] A critical stored XSS vulnerability in SiYuan's personal knowledge management system has been patched in version 3.6.2, preventing potential cyber attacks through malicious URLs.#cve,CVE-2026-34448,#cybersecurity https://cvefind.com/CVE-2026-34448

    Post summary

    The post reports that CVE-2026-34448 is a critical stored XSS vulnerability in SiYuan, which has already been patched in version 3.6.2, removing the threat.

    0000050
    617 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appb3logsiyuan---

Explore more