CVE-2026-93923 Overview
CVE-2026-93923 is a stored cross-site scripting (XSS) vulnerability in the SiYuan note-taking application through version 3.8.4. The flaw resides in the rendering logic for outline and bookmark dock HTML, where heading style attributes are not properly escaped. Attackers can supply crafted notebooks or invoke administrative endpoints to inject malicious style values. Because SiYuan runs inside an Electron renderer, injected payloads execute with full system access on the victim host. The issue is tracked under [CWE-79] and documented in GitHub Security Advisory GHSA-928g.
Critical Impact
Successful exploitation yields arbitrary JavaScript execution in the Electron renderer, enabling full local system compromise of the SiYuan user.
Affected Products
- SiYuan note-taking application, all versions through 3.8.4
- SiYuan Electron desktop client (Windows, macOS, Linux builds)
- SiYuan kernel render model exposed via administrative endpoints
Discovery Timeline
- 2026-09-19 - CVE-2026-93923 published to the National Vulnerability Database
- 2026-09-21 - Last updated in NVD database
Technical Details for CVE-2026-93923
Vulnerability Analysis
SiYuan renders document outlines and bookmarks by constructing HTML strings that include heading attributes copied from the underlying block model. The rendering path fails to escape the style attribute value before insertion into the DOM. An attacker who can influence heading style data, either by importing a crafted notebook or by calling administrative endpoints that mutate blocks, can break out of the attribute context. The injected content executes inside the Electron renderer, which exposes Node.js integration and native file system access. This elevates a browser-class XSS into arbitrary code execution on the operating system. Relevant code paths appear in Tree.ts line 133, Tree.ts line 194, and the render model in render.go.
Root Cause
The root cause is missing output encoding on heading style attribute values during dock HTML generation. Attribute-context sanitization is absent in both the TypeScript UI utilities and the Go kernel render layer, allowing attribute breakout characters to survive to the rendered DOM.
Attack Vector
Exploitation is network-reachable and requires user interaction, such as opening a malicious notebook or navigating to a document with the poisoned heading. Attackers with access to administrative endpoints can inject payloads directly without user cooperation from a second victim.
// No verified proof-of-concept code is published for CVE-2026-93923.
// See the GHSA-928g-4hfq-qwvx advisory and the referenced Tree.ts
// and render.go lines for the vulnerable rendering paths.
Detection Methods for CVE-2026-93923
Indicators of Compromise
- Heading blocks containing style attribute values with ", <, >, or javascript: tokens or embedded HTML tags
- Notebook imports from untrusted sources followed by unexpected child processes spawned by the SiYuan Electron process
- Outbound network connections from the SiYuan renderer to unfamiliar hosts shortly after opening a document
Detection Strategies
- Inspect SiYuan notebook JSON and block data for heading elements whose style attribute contains angle brackets, quote characters, or event handler substrings such as onerror= or onload=
- Alert on the SiYuan Electron process launching shells, script interpreters, or LOLBins that are atypical for a note-taking application
- Correlate file writes to SiYuan data directories from non-SiYuan processes, which may indicate malicious notebook staging
Monitoring Recommendations
- Enable endpoint process telemetry to capture child process trees originating from the SiYuan Electron binary
- Monitor administrative API calls to the SiYuan kernel that mutate block attributes, especially from unauthenticated or unexpected sources
- Retain browser and application logs so heading attribute anomalies can be traced back to the originating notebook import
How to Mitigate CVE-2026-93923
Immediate Actions Required
- Upgrade SiYuan to a release published after version 3.8.4 that includes the fix referenced in GHSA-928g-4hfq-qwvx
- Avoid importing notebooks or opening .sy archives from untrusted sources until patched
- Restrict network exposure of the SiYuan kernel administrative endpoints to trusted hosts only
Patch Information
Refer to the Siyuan Project Repository and the VulnCheck advisory for the fixed version and commit details. The remediation adds attribute-context escaping to heading style values in both the Tree.ts outline and bookmark helpers and the kernel render.go output.
Workarounds
- Run SiYuan under a low-privilege user account to limit the impact of renderer-side code execution
- Bind the SiYuan kernel listener to 127.0.0.1 and place it behind an authenticated reverse proxy to prevent remote administrative calls
- Disable auto-open of shared notebooks and manually review heading blocks in any third-party content before import
# Configuration example: restrict the SiYuan kernel to localhost only
siyuan --host 127.0.0.1 --port 6806 --accessAuthCode <strong-random-value>
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.