Security Advisory

CVE-2026-54759

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-24 21:21:57
Last updated 2026-06-25 12:32:38
Assigner GitHub_M
CVSS score 8.7
State PUBLISHED

Description

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, Lute's HTML sanitizer does not remove <iframe> elements. Combined with the SiYuan Electron client's permissive security configuration, an attacker can include a malicious <iframe> in a Bazaar package README that executes arbitrary commands on the victim's machine when the package details are viewed. No package installation is required. This vulnerability is fixed in 3.7.0.