CVE-2026-50551

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in the Attribute View (database) asset cell renderer that escalates to remote code execution (RCE) in the Electron desktop client. This vulnerability is fixed in 3.7.0.
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-24 22:16

Updated : 2026-06-25 14:16


NVD link : CVE-2026-50551

Mitre link : CVE-2026-50551

CVE.ORG link : CVE-2026-50551


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')