Israel[verified]@f1tym1Disclosure
The post discloses a new Electron Renderer RCE vulnerability in SiYuan, references incomplete fixes, and links to the source repo, but does not provide exploit code or evidence of active exploitation.
CVE@CVEnewDisclosure
The CVE-2026-34585 vulnerability in SiYuan permits crafted block attribute values to circumvent server‑side attribute escaping in versions prior to 3.6.2.
The Hacker Wire@TheHackerWireDisclosure
The post announces CVE‑2026‑34585, describing how crafted block attribute values can bypass server‑side escaping, and indicates that versions before 3.6.2 are vulnerable.
CVEFind.com@CveFindComPatch
The post announces a High severity CVE-2026-34585 in SiYuan that allows stored XSS in .sy documents, resulting in remote code execution, and recommends updating to version 3.6.2 to apply the fix.