top of page
perceptive_background_267k.jpg

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable f…

Published:

2 september 2026 om 00:00:00

Alert date:

2 september 2026 om 16:04:55

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

SiYuan versions before v3.8.2 are affected by a stored cross-site scripting (XSS) vulnerability in the asset serving component. The vulnerability stems from an incomplete file extension blocklist that fails to block script-capable file types such as .xht, .ehtml, .xsl, .xbl, and .rdf. Attackers who can upload files to a SiYuan instance can exploit this flaw by uploading files with these extensions, which resolve to executable media types in browsers. Once a victim views or accesses such a file, malicious JavaScript is executed in their browser context. This can result in theft of API tokens and full compromise of user workspaces. The vulnerability is classified as stored XSS, making it persistent and potentially high-impact. A patch was released in SiYuan v3.8.2 which addresses the incomplete blocklist. Users are strongly advised to upgrade to v3.8.2 or later to mitigate this risk.

Technical details

Mitigation steps:

Affected products:

SiYuan

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page