CVE-2026-39846Disclosure(b3log / siyuan)

MEDIUMCVSS 9.0 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch b3log siyuan systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption content is stored without safe escaping and later unescaped into rendered HTML, creating a stored XSS sink. Because the desktop renderer runs with nodeIntegration enabled and contextIsolation disabled, attacker-controlled JavaScript executes with access to Node.js APIs. In practice, an attacker can import a crafted note into a synced workspace, wait for the victim to sync, and achieve code execution when the victim opens the note. This vulnerability is fixed in 3.6.4.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • siyuan

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-07); latest day: 2
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
siyuan

Deep dive

Activity timeline6 mentions / 3d
01122Mentions · 2026-04-07: 2Mentions · 2026-04-08: 2Mentions · 2026-04-09: 2PoC Mentioned / Linked · 2026-04-09: 1Exploit Tool / Code · 2026-04-09: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-04-09: 1Technical Details · 2026-04-07: 2Technical Details · 2026-04-08: 2Technical Details · 2026-04-09: 204-0704-0804-09
Signal classification3 categories
Disclosure
466.7%
Patch
116.7%
PoC
116.7%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-04-072
Disclosure1Patch1
2026-04-082
Disclosure2
2026-04-092
Disclosure1PoC1
Full discourse6 posts
  • Mr. OS@ksg93rd
    PoC

    #AppSec 1⃣ RCE in the Electron desktop client via stored XSS in synced table captions https://github.com/advisories/GHSA-phhp-9rm9-6gr2 // Critical CVE-2026-39846, 9.1/10 2⃣ GhidraServer PKI User Impersonation via Null Signature https://github.com/califio/publications/tree/main/MADBugs/ghidra-server // Null-signature flaw in GhidraServer's PKI authentication module allows any user with a valid CA-signed certificate to impersonate any other user on the server 3⃣ SandboxJS: Sandbox integrity escape https://github.com/advisories/GHSA-2gg9-6p7w-6cpj // Critical CVE-2026-34208, 10/10

    Post summary

    The tweet lists three critical CVEs with links to GitHub advisories that contain proof‑of‑concept details and explains exploitation methods, yet it does not mention active exploitation or any patches.

    00011218
    3.2K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    The `SiYuan` Electron desktop client is vulnerable to RCE (CVE-2026-39846) via stored XSS in table captions. Users should monitor for official patches. #RCE #XSS #infosec https://www.pulsepatch.io/posts/cve-2026-39846-siyuan-rce-xss

    Post summary

    The post announces a new RCE vulnerability in the SiYuan Electron desktop client caused by stored XSS, advises users to await official patches, and provides technical details of the flaw.

    0000052
    11 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39846 SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron des… https://www.cve.org/CVERecord?id=CVE-2026-39846

    Post summary

    The CVE describes a remote code execution flaw in SiYuan’s Electron app, fixable by upgrading to version 3.6.4, with no PoC, exploit tools, or active exploitation reported.

    00000151
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-39846 Remote Code Execution in SiYuan Desktop Client via Stored XSS in Table Captions https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39846

    Post summary

    The text announces the CVE-2026-39846 vulnerability, detailing it as a Remote Code Execution via stored XSS in SiYuan Desktop Client table captions, without mentioning a PoC, exploit, active attacks, or patches.

    0000041
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-39846: CRITICAL] Vulnerability in SiYuan's knowledge management system allows remote code execution pre-3.6.4. Update to 3.6.4 to patch this stored XSS vulnerability.#cve,CVE-2026-39846,#cybersecurity https://cvefind.com/CVE-2026-39846

    Post summary

    The post announces a remote code execution vulnerability in SiYuan pre‑3.6.4 and advises upgrading to 3.6.4 to apply the available patch.

    0000049
    619 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-39846: SiYuan affected by Remote Code E... Electron's nodeIntegration + contextIsolation combo strikes again - stored XSS in table captions becomes instant RCE wh... https://zerodaysignal.com/vulnerability/CVE-2026-39846 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    This tweet announces CVE-2026-39846, noting that stored XSS in table captions causes remote code execution in SiYuan's Electron app, and provides a link to additional details.

    0000051
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appb3logsiyuan---

Explore more