CVE-2026-87812

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in Bazaar package cards where the iconURL metadata is inserted directly into HTML img src attributes without escaping. Attackers can inject malicious URLs with event handlers that execute JavaScript in the authenticated SiYuan origin when users view Bazaar listings, enabling API requests and application state manipulation.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 12:17

Updated : 2026-09-10 15:17


NVD link : CVE-2026-87812

Mitre link : CVE-2026-87812

CVE.ORG link : CVE-2026-87812


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')