NONE · 0

CVE-2026-59833

SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content to HTML through the Lute engine with sanitization enabled, but Lute's dangerous j...

Vulnerability Description

SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content to HTML through the Lute engine with sanitization enabled, but Lute's dangerous javascript scheme block does not check form action or SVG xlink:href attributes, allowing stored cross-site scripting in document export-preview and Bazaar package README render paths that can execute OS commands in the Electron desktop renderer. This issue is fixed in versions 3.7.1.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-59833?

CVE-2026-59833 is a documented vulnerability. SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content to HTML through the Lute engine with sanitization enabled, but Lute's dangerous j...

How severe is CVE-2026-59833?

CVSS scoring is not yet available for CVE-2026-59833. Check NVD for updates.

Is there a patch for CVE-2026-59833?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.