CVE-2026-66394 Details
Description
SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows authenticated attackers to execute scripts by bypassing the HTML parser-based cleaner. Attackers can hide script tags within desc, style, or noscript elements which the HTML parser treats as raw text but browsers interpret as executable SVG content when served as image/svg+xml, enabling script execution in the application origin.
A stored and reflected cross-site scripting vulnerability has been identified in SiYuan versions prior to 3.7.3. This issue arises from improper sanitization of SVG files, allowing authenticated attackers to execute scripts by circumventing the HTML parser-based cleaner. The vulnerability exploits the fact that script tags can be hidden within desc, style, or noscript elements, which are treated as raw text by the HTML parser but interpreted as executable SVG content by browsers when served as image/svg+xml. This enables script execution in the application origin.
Users are advised to update to SiYuan version 3.7.3 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 27, 2026CISA-ADP
Assessed Jul 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/siyuan-note/siyuan/security/advisories/GHSA-99rq-75j6-5j9f | CISA-ADP | AdvisoryExploitRemedyTechnical AnalysisVendor |
| https://github.com/siyuan-note/siyuan/security/advisories/GHSA-99rq-75j6-5j9f | [email protected] | AdvisoryExploitRemedyTechnical AnalysisVendor |
| https://www.vulncheck.com/advisories/siyuan-before-stored-and-reflected-xss-via-svg-sanitizer-bypass | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SiYuan | <= 3.7.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 27, 2026 | CVE Modified | CISA-ADP |
| Jul 27, 2026 | New CVE Received | [email protected] |
Volerion