CVE-2026-59833General

LOWCVSS 8.6 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content to HTML through the Lute engine with sanitization enabled, but Lute's dangerous javascript scheme block does not check form action or SVG xlink:href attributes, allowing stored cross-site scripting in document export-preview and Bazaar package README render paths that can execute OS commands in the Electron desktop renderer. This issue is fixed in versions 3.7.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94CWE-116

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-10: 2Patch / Workaround · 2026-07-10: 1Technical Details · 2026-07-10: 107-10
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-59833 SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content to HTML through the Lute engine with sanitizati… https://www.cve.org/CVERecord?id=CVE-2026-59833 ----- Traducción: CVE-2026-59833 SiY… http://infoflow.cloud`

    Post summary

    The post notes a CVE for SiYuan, indicating a rendering issue before version 3.7.1, but provides no further technical, exploit, or patch details.

    0000049
    91 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-59833 SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content to HTML through the Lute engine with sanitizati… https://www.cve.org/CVERecord?id=CVE-2026-59833

    Post summary

    CVE-2026-59833 exposes a sanitization issue in SiYuan's Lute engine; it is addressed in version 3.7.1 and no PoC, exploit, or active attacks are reported.

    00000611
    57.8K followersView on X

Explore more