
🚨 High - SiYuan Marketplace Stored XSS → RCE (CVE-2026-45375) A critical stored XSS in SiYuan's Bazaar marketplace allows attackers to inject malicious HTML via unsanitized name and version fields in package metadata. Because the Electron desktop client runs with nodeIntegration: true and contextIsolation: false, the XSS escalates to arbitrary OS command execution the moment a user opens the marketplace tab — no install action required. 👉 Affected: http://github.com/siyuan-note/siyuan/kernel ≤ 0.0.0-20260421031503-96dfe0bea474 | No patch available
Post summary
A high‑severity stored XSS in SiYuan's Bazaar marketplace leads to RCE via unsanitized metadata, with no patch available and no PoC or exploit tools referenced, and no evidence of active exploitation.

