


Perceptive Security
SOC/SIEM Consultancy

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable f…
Published:
2 september 2026 om 00:00:00
Alert date:
2 september 2026 om 16:04:55
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
SiYuan versions before v3.8.2 are affected by a stored cross-site scripting (XSS) vulnerability in the asset serving component. The vulnerability stems from an incomplete file extension blocklist that fails to block script-capable file types such as .xht, .ehtml, .xsl, .xbl, and .rdf. Attackers who can upload files to a SiYuan instance can exploit this flaw by uploading files with these extensions, which resolve to executable media types in browsers. Once a victim views or accesses such a file, malicious JavaScript is executed in their browser context. This can result in theft of API tokens and full compromise of user workspaces. The vulnerability is classified as stored XSS, making it persistent and potentially high-impact. A patch was released in SiYuan v3.8.2 which addresses the incomplete blocklist. Users are strongly advised to upgrade to v3.8.2 or later to mitigate this risk.
Technical details
Mitigation steps:
Affected products:
SiYuan
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-84803
https://github.com/siyuan-note/siyuan/security/advisories/GHSA-7h8j-qw37-w46g
https://www.vulncheck.com/advisories/siyuan-before-3.8.2-stored-xss-via-incomplete-asset-blocklist
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
