CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-66395 — SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerabi...

·Source: NIST NVD

Updated:

Executive Summary

SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter that execute with full Node.js access through insertAdjacentHTML rendering in an insecurely configured Electron renderer.

Analysis

SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter that execute with full Node.js access through insertAdjacentHTML rendering in an insecurely configured Electron renderer. CVSS Score: 9.6. Published: 2026-07-27T16:18:12.083.

Indicators of Compromise (1)

CVE (1)
CVE-2026-66395
Source Attribution

Originally published by NIST NVD on Jul 27, 2026. Verified by: NIST.

Related Threats