CVE-2026-40322Disclosure(b3log / siyuan)

LOWCVSS 9.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to "loose", and the resulting SVG is injected into the DOM via innerHTML. This allows attacker-controlled javascript: URLs in Mermaid code blocks to survive into the rendered output. On desktop builds using Electron, windows are created with nodeIntegration enabled and contextIsolation disabled, escalating the stored XSS to arbitrary code execution when a victim opens a note containing a malicious Mermaid block and clicks the rendered diagram node. This issue has been fixed in version 3.6.4.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • siyuan

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-04-16); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
siyuan

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-16: 1Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Mentions · 2026-05-03: 1PoC Mentioned / Linked · 2026-04-16: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-17: 104-1604-1704-1805-03
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-161
Disclosure1
2026-04-171
Disclosure1
2026-04-181
General1
2026-05-031
General1
Full discourse4 posts
  • ケイ | 副業Webライター🇫🇷⚓⚽@Teeeda_worker
    General

    【アーカイブ】 【脆弱性情報】 CVE-2026-40322 b3logのsiyuanの脆弱性について https://www.cybernote.click/2026/04/21/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-40322-b3log%e3%81%aesiyuan%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6/?utm_source=rss&utm_medium=rss&utm_campaign=%25e3%2580%2590%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25e6%2583%2585%25e5%25a0%25b1%25e3%2580%2591-cve-2026-40322-b3log%25e3%2581%25aesiyuan%25e3%2581%25ae%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25e3%2581%25ab%25e3%2581%25a4%25e3%2581%2584%25e3%2581%25a6 #ブログ仲間と繋がりたい #Webライター

    Post summary

    A concise announcement of CVE-2026-40322 affecting b3log’s siyuan product, providing only a link to further information without additional technical details, PoCs, or usage reports.

    0000043
    210 followersView on X
  • VulDB 🛡@vuldb
    General

    It is possible to see elevated activities targeting SiYuan (CVE-2026-40322) https://vuldb.com/vuln/357992/cti

    Post summary

    The post briefly references CVE-2026-40322 for SiYuan and links to a vulnerability page, but it offers no technical details or evidence of exploitation.

    0000071
    2.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40322 SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to "loose", and the r… https://www.cve.org/CVERecord?id=CVE-2026-40322

    Post summary

    The post announces CVE‑2026‑40322, noting insecure Mermaid diagram rendering in older SiYuan versions; no PoC, exploit, patch, or active exploitation details are provided.

    0000069
    57.2K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40322: SiYuan: Mermaid `javascript:` Li... Mermaid's loose security + Electron's nodeIntegration = game over - one malicious diagram click gets you full RCE on th... https://zerodaysignal.com/vulnerability/CVE-2026-40322 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑40322, highlighting that a single malicious Mermaid diagram can exploit Electron’s nodeIntegration to achieve full RCE in SiYuan; no patches, exploit code, or active exploitation reports are included.

    0000059
    218 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appb3logsiyuan---

Explore more