SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in Bazaar package cards where the iconURL metadata is inserted directly into HTML img src attributes without escaping. Attackers can inject malicious URLs with event handlers that execute JavaScript in the authenticated SiYuan origin when users view Bazaar listings, enabling API requests and application state manipulation.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 12:17
Updated : 2026-09-10 15:17
NVD link : CVE-2026-87812
Mitre link : CVE-2026-87812
CVE.ORG link : CVE-2026-87812
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
