Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 14 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metadata from the public bazaar stage feed into HTML without escaping. In the desktop app this becomes stored XSS, and because SiYuan's Electron windows are created with nodeIntegration: true and contextIsolation: false, a successful payload can call Node.js APIs and execute code on the host. This vulnerability is fixed in 3.7.0. | |
| Title | SiYuan: Bazaar marketplace renders unescaped package author metadata, allowing XSS and Electron code execution | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-14T19:35:27.517Z
Reserved: 2026-05-06T21:49:12.425Z
Link: CVE-2026-44586
Updated: 2026-05-14T19:35:10.686Z
Status : Deferred
Published: 2026-05-14T19:16:37.727
Modified: 2026-05-14T21:22:56.313
Link: CVE-2026-44586
No data.
OpenCVE Enrichment
Updated: 2026-05-14T21:15:16Z