CVE-2026-93922

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaScript with Node.js access when the picker opens, enabling operating system command execution.

  • Published Sep 19, 2026
  • CVSS 8.6 high
  • 0.8% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-93922 at the National Vulnerability Database