SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. Attackers can upload files with extensions like .xht, .ehtml, .xsl, .xbl, or .rdf that resolve to executable media types and execute JavaScript to steal API tokens and compromise workspaces.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-02 12:17
Updated : 2026-09-02 14:17
NVD link : CVE-2026-84803
Mitre link : CVE-2026-84803
CVE.ORG link : CVE-2026-84803
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
