CRITICAL 9 CVE-2026-84803 Published 2 Sept 2026

SiYuan XSS Vulnerability in Asset Serving

Worried this affects one of your servers?

SiYuan versions before 3.8.2 contain a stored cross-site scripting (XSS) vulnerability in asset serving.

SiYuan fails to block script-capable file types, allowing attackers to upload files with extensions like .xht, .ehtml, .xsl, .xbl, or .rdf that can execute JavaScript.

Exploiting this vulnerability, attackers can steal API tokens and compromise workspaces.

Reference: CVE-2026-84803 on NVD

← Back to Security News