ZeroHour

CVE-2026-87812

niche

Stored XSS in SiYuan Bazaar package cards via iconURL metadata

CVSS 4.0
7.4 high
EPSS
Published
()
Modified
AI analysis

SiYuan before v3.8.2 is vulnerable to a stored cross-site scripting flaw in its Bazaar package marketplace cards: the iconURL metadata of a package is inserted directly into HTML img src attributes without escaping. An attacker who controls the iconURL of a package (for example by publishing or modifying a marketplace entry) can inject a URL with event handlers such as onerror, and the payload executes when an authenticated user views the Bazaar listings. The injected JavaScript runs in the authenticated SiYuan origin, letting the attacker issue API requests as the victim and manipulate application state such as notes and settings. All SiYuan users running a version prior to 3.8.2 who browse the Bazaar marketplace are affected. No public proof-of-concept is known and the flaw is not in the CISA KEV catalog, so no exploitation is currently documented.

What to do: Upgrade to SiYuan v3.8.2 or later. Until patched, avoid browsing Bazaar listings and treat marketplace package metadata (including iconURL values) as untrusted, reviewing installed or published packages for unexpected icon URLs. No public proof-of-concept or in-the-wild exploitation is known at this time.

Affected
SiYuan (B3log) SiYuanbefore v3.8.2
Estimated exposure
nichelikely in the low tens of thousands of active users (no public active-install counts) — SiYuan is a niche open-source desktop/self-hosted note-taking application with no published active-install counts, and exposure requires an authenticated user to browse the Bazaar marketplace while a malicious iconURL is present, which…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in Bazaar package cards where the iconURL metadata is inserted directly into HTML img src attributes without escaping. Attackers can inject malicious URLs with event handlers that execute JavaScript in the authenticated SiYuan origin when users view Bazaar listings, enabling API requests and application state manipulation.

Weakness
CWE-79
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.