CVE-2026-100643 Overview
CVE-2026-100643 is a stored cross-site scripting (XSS) vulnerability [CWE-79] affecting SiYuan note-taking application versions before v3.8.4. The flaw stems from improper escaping of four Attribute View values rendered inside textarea elements. Authenticated attackers can inject JavaScript by modifying field descriptions, template sources, select option descriptions, or footer calculation templates. The payload executes when another user opens the affected database menu. When SiYuan runs as an Electron desktop application with nodeIntegration enabled, the injected JavaScript escalates to arbitrary command execution under the privileges of the SiYuan process.
Critical Impact
Stored JavaScript executes in victim sessions and can escalate to host command execution in the Electron desktop client.
Affected Products
- SiYuan note-taking application versions prior to v3.8.4
- SiYuan Electron desktop client with nodeIntegration enabled
- Shared or collaborative SiYuan workspaces where multiple users access Attribute Views
Discovery Timeline
- 2026-09-26 - CVE-2026-100643 published to the National Vulnerability Database
- 2026-09-28 - Last updated in NVD database
Technical Details for CVE-2026-100643
Vulnerability Analysis
SiYuan's Attribute View feature allows users to define database-style metadata for notes, including field descriptions, template sources, select option descriptions, and footer calculation templates. These four fields are rendered inside HTML textarea elements without adequate output encoding. An authenticated attacker with write access to an Attribute View can store attacker-controlled markup in any of these fields. When another user subsequently opens a database menu that renders the stored value, the browser parses the injected content and executes attacker-supplied JavaScript in the context of the SiYuan web origin.
The impact extends beyond browser-based XSS. SiYuan ships as an Electron desktop application, and when nodeIntegration is enabled the renderer process can access Node.js APIs. Injected JavaScript can call modules such as child_process to spawn operating system commands with the privileges of the SiYuan process. This converts a stored XSS primitive into reliable remote command execution on any workstation that opens the malicious Attribute View.
Root Cause
The root cause is missing contextual output encoding when writing user-supplied strings into textarea DOM nodes. The affected sinks do not escape characters such as <, >, and </textarea> closing sequences, allowing an attacker to break out of the textarea context and inject <script> or event handler markup that the browser executes.
Attack Vector
Exploitation requires an authenticated SiYuan user with permission to edit Attribute View metadata. The attacker modifies one of the four unescaped fields, embeds a JavaScript payload, and waits for a victim to open the affected database menu. User interaction, specifically opening the menu, is required for execution. In Electron builds with nodeIntegration enabled, the payload can invoke Node.js APIs to execute arbitrary commands locally.
See the GitHub Security Advisory GHSA-h3p6-c22r-fx2j and the VulnCheck Stored XSS Advisory for additional technical context.
Detection Methods for CVE-2026-100643
Indicators of Compromise
- Attribute View fields containing HTML tags, </textarea> sequences, or <script> fragments in field descriptions, template sources, select option descriptions, or footer calculation templates.
- Unexpected child processes spawned by the SiYuan Electron process, such as cmd.exe, powershell.exe, /bin/sh, or bash on desktop clients.
- Outbound network connections from the SiYuan process to attacker-controlled hosts shortly after a user opens a shared database.
Detection Strategies
- Audit stored Attribute View values in SiYuan workspaces for HTML or JavaScript syntax that should not appear in free-text metadata fields.
- Monitor Electron desktop endpoints for process lineage where SiYuan spawns command interpreters or scripting hosts.
- Review browser or Electron DevTools console errors indicating script execution originating from database menu rendering.
Monitoring Recommendations
- Enable endpoint telemetry that captures parent-child process relationships for the SiYuan binary across Windows, macOS, and Linux clients.
- Alert on SiYuan processes initiating network connections to non-standard destinations.
- Track SiYuan version strings across managed endpoints to identify instances still running builds earlier than v3.8.4.
How to Mitigate CVE-2026-100643
Immediate Actions Required
- Upgrade all SiYuan instances to version v3.8.4 or later, which properly escapes the affected textarea values.
- Inventory shared workspaces and remove suspicious content from Attribute View field descriptions, template sources, select option descriptions, and footer calculation templates.
- Restrict Attribute View edit permissions to trusted users while remediation is in progress.
Patch Information
The maintainers released SiYuan v3.8.4 to address the missing output encoding in the four Attribute View sinks. Upgrade instructions and release details are available in the GitHub Security Advisory GHSA-h3p6-c22r-fx2j.
Workarounds
- Disable nodeIntegration in Electron desktop deployments to prevent XSS payloads from reaching Node.js APIs and executing shell commands.
- Avoid opening Attribute View database menus in untrusted or shared workspaces until the upgrade is applied.
- Isolate SiYuan clients from sensitive host resources where upgrading is not immediately feasible.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.