CVE-2026-56395Disclosure

LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Rejected reason: This record is a duplicate; use CVE-2026-56397 instead.

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-21: 2Patch / Workaround · 2026-06-21: 1Technical Details · 2026-06-21: 206-21
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - SiYuan Bazaar Marketplace XSS-to-RCE via Package Metadata (CVE-2026-56395) SiYuan fails to sanitize package metadata and README content in its Bazaar marketplace, so a malicious package author can inject arbitrary HTML and JavaScript through the displayName, description, or README fields. When another user browses the Bazaar, the stored payload executes in the app. Because SiYuan is an Electron app with nodeIntegration enabled, the XSS escapes the browser context and can run OS-level commands, turning a marketplace listing into remote code execution against anyone viewing it. Exploitation requires only that a victim browse the Bazaar. 👉Upgrade to SiYuan v3.6.1.

    Post summary

    CVE‑2026‑56395 is a critical XSS‑to‑RCE in the SiYuan Bazaar marketplace that requires only a victim to browse a malicious listing; upgrading to v3.6.1 mitigates the issue.

    0000088
    223 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-56395 Cross-Site Scripting and Remote Code Execution in SiYuan Bazaar Before v3.6.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-56395

    Post summary

    CVE‑2026‑56395 is an XSS and RCE vulnerability in SiYuan Bazaar before v3.6.1; the provided link only supplies basic disclosure details without PoC, exploit, or patch information.

    0000054
    4.1K followersView on X

Explore more