CVE-2026-41421Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, SiYuan desktop renders notification messages as raw HTML inside an Electron renderer. The notification route POST /api/notification/pushMsg accepts a user-controlled msg value, forwards it through the backend broadcast layer, and the frontend inserts it into the DOM with insertAdjacentHTML(...) at message.ts. On desktop builds, this is not limited to ordinary XSS. Electron windows are created with nodeIntegration: true, contextIsolation: false, and webSecurity: false at main.js. As a result, JavaScript executed from the notification sink can directly access Node APIs and escalate to desktop code execution. This vulnerability is fixed in 3.6.5.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-05-22)
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-24: 1Mentions · 2026-04-25: 1Mentions · 2026-05-22: 2Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 1Technical Details · 2026-05-22: 204-2404-2505-22
Signal classification1 categories
Disclosure
4100.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-241
Disclosure1
2026-04-251
Disclosure1
2026-05-222
Disclosure2
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-41421 is a high-severity vulnerability (CVSS 8.8) in SiYuan, a popular open-source personal knowledge management system. The flaw allows remote code execution on desktop builds through a simple HTML injection attack vector in notification messages. Affected…

    Post summary

    High‑severity RCE in SiYuan disclosed, with technical details but no PoC, exploit code, or patch info.

    1000047
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    41421 is — SiYuan Electron RCE: How HTML Injection Became Desktop Code Execution (CVE-2026-41421). CVE-2026-41421 is a high-severity vulnerability CVSS 8.8 in SiYuan, a popular open-source personal knowledge management system.

    Post summary

    The post announces CVE‑2026‑41421, a high‑severity RCE in SiYuan Electron, but provides no PoC, exploit, patch, or evidence of active exploitation.

    1000046
    227 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41421 SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, SiYuan desktop renders notification messages as raw HTML inside an Electron renderer. T… https://www.cve.org/CVERecord?id=CVE-2026-41421

    Post summary

    The post announces CVE‑2026‑41421, noting that SiYuan desktop renders notifications as raw HTML within an Electron renderer, implying an XSS vulnerability. No PoC, exploit, patch, or active exploitation is mentioned.

    00010105
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41421 Cross-Site Scripting to Remote Code Execution in SiYuan Desktop Before 3.6.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41421

    Post summary

    The post announces CVE-2026-41421, describing a XSS-to-RCE flaw in SiYuan Desktop, but provides no PoC, exploit code, active usage or patch information.

    0000061
    4.0K followersView on X

Explore more