
🚨Critical - SiYuan Bazaar Marketplace XSS-to-RCE via Package Metadata (CVE-2026-56397) SiYuan fails to sanitize package metadata and README content in its Bazaar marketplace, so a malicious package author can inject arbitrary HTML and JavaScript through the displayName, description, or README fields. When another user browses the Bazaar, the stored payload executes in the app. Because SiYuan is an Electron app with nodeIntegration enabled, the XSS escapes the browser context and can run OS-level commands, turning a marketplace listing into remote code execution against anyone viewing it. Exploitation requires only that a victim browse the Bazaar. 👉Upgrade to SiYuan v3.6.1.
Post summary
SiYuan’s Bazaar Marketplace allows malicious package authors to inject HTML/JS into package metadata, which escalates to OS‑level RCE due to the Electron app’s nodeIntegration. A patch is available in v3.6.1.

