
🚨Critical - SiYuan Bazaar Marketplace XSS-to-RCE via Package Metadata (CVE-2026-56395) SiYuan fails to sanitize package metadata and README content in its Bazaar marketplace, so a malicious package author can inject arbitrary HTML and JavaScript through the displayName, description, or README fields. When another user browses the Bazaar, the stored payload executes in the app. Because SiYuan is an Electron app with nodeIntegration enabled, the XSS escapes the browser context and can run OS-level commands, turning a marketplace listing into remote code execution against anyone viewing it. Exploitation requires only that a victim browse the Bazaar. 👉Upgrade to SiYuan v3.6.1.
Post summary
CVE‑2026‑56395 is a critical XSS‑to‑RCE in the SiYuan Bazaar marketplace that requires only a victim to browse a malicious listing; upgrading to v3.6.1 mitigates the issue.

