Beveiligingsadvies
CVE-2026-82654
CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations
Beschrijving
SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags that execute when another user views documents referencing or displaying that block.