CVE-2026-56397Disclor

LOWCVSS 9.4 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclor: 1 classified signal
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-21: 2Patch / Workaround · 2026-06-21: 1Technical Details · 2026-06-21: 206-21
Signal classification2 categories
Disclor
150.0%
Disclosure
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Disclor

    🚨Critical - SiYuan Bazaar Marketplace XSS-to-RCE via Package Metadata (CVE-2026-56397) SiYuan fails to sanitize package metadata and README content in its Bazaar marketplace, so a malicious package author can inject arbitrary HTML and JavaScript through the displayName, description, or README fields. When another user browses the Bazaar, the stored payload executes in the app. Because SiYuan is an Electron app with nodeIntegration enabled, the XSS escapes the browser context and can run OS-level commands, turning a marketplace listing into remote code execution against anyone viewing it. Exploitation requires only that a victim browse the Bazaar. 👉Upgrade to SiYuan v3.6.1.

    Post summary

    SiYuan’s Bazaar Marketplace allows malicious package authors to inject HTML/JS into package metadata, which escalates to OS‑level RCE due to the Electron app’s nodeIntegration. A patch is available in v3.6.1.

    0000071
    223 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-56397 Cross-Site Scripting and Remote Code Execution in SiYuan Bazaar Before v3.6.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-56397

    Post summary

    The entry announces CVE‑2026‑56397, noting it enables XSS and RCE in SiYuan Bazaar prior to version 3.6.1, but gives no PoC, patch, or exploitation evidence.

    0000057
    4.1K followersView on X

Explore more