CVE-2026-84803

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. Attackers can upload files with extensions like .xht, .ehtml, .xsl, .xbl, or .rdf that resolve to executable media types and execute JavaScript to steal API tokens and compromise workspaces.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-02 12:17

Updated : 2026-09-02 14:17


NVD link : CVE-2026-84803

Mitre link : CVE-2026-84803

CVE.ORG link : CVE-2026-84803


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')