CVE-2026-34585Disclosure(b3log / siyuan)

LOWCVSS 8.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch b3log siyuan systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute values to bypass server-side attribute escaping when an HTML entity is mixed with raw special characters. An attacker can embed a malicious IAL value inside a .sy document, package it as a .sy.zip, and have the victim import it through the normal Import -> SiYuan .sy.zip workflow. Once the note is opened, the malicious attribute breaks out of its original HTML context and injects an event handler, resulting in stored XSS. In the Electron desktop client, this XSS reaches remote code execution because injected JavaScript runs with access to Node/Electron APIs. This issue has been patched in version 3.6.2.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • siyuan

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-01); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
siyuan

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-31: 1Mentions · 2026-04-01: 2Mentions · 2026-05-20: 1PoC Mentioned / Linked · 2026-05-20: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-05-20: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 2Technical Details · 2026-05-20: 103-3104-0105-20
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-311
Patch1
2026-04-012
Disclosure2
2026-05-201
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-34585 SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute values to bypass server-side attribute escapi… https://www.cve.org/CVERecord?id=CVE-2026-34585

    Post summary

    The CVE-2026-34585 vulnerability in SiYuan permits crafted block attribute values to circumvent server‑side attribute escaping in versions prior to 3.6.2.

    0001093
    56.9K followersView on X
  • Israel@f1tym1
    Disclosure

    GO-2026-4993 — Go: SiYuan: Electron Renderer RCE via decodeURIComponent-driven tooltip XSS in aria-label sink (incomplete fix for CVE-2026-34585) in http://github.com/siyuan-note/siyuan/kernel https://ift.tt/oNrkfYW SiYuan: Electron Renderer RCE via decodeURIComponent-driv… http://github.com/siyuan-note/siyuan/kernel

    Post summary

    The post discloses a new Electron Renderer RCE vulnerability in SiYuan, references incomplete fixes, and links to the source repo, but does not provide exploit code or evidence of active exploitation.

    0000051
    974 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-34585 - High SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute values to bypass server-side attribute escaping when an HTML entity is... https://www.thehackerwire.com/vulnerability/CVE-2026-34585/ https://t.co/9X1ovb6tnM

    Post summary

    The post announces CVE‑2026‑34585, describing how crafted block attribute values can bypass server‑side escaping, and indicates that versions before 3.6.2 are vulnerable.

    0000050
    163 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34585: HIGH] Vulnerability in SiYuan prior to version 3.6.2 allowed a malicious .sy document to execute stored XSS leading to remote code execution. Update to version 3.6.2 to patch the issue.#cve,CVE-2026-34585,#cybersecurity https://cvefind.com/CVE-2026-34585

    Post summary

    The post announces a High severity CVE-2026-34585 in SiYuan that allows stored XSS in .sy documents, resulting in remote code execution, and recommends updating to version 3.6.2 to apply the fix.

    0000054
    617 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appb3logsiyuan---

Explore more