What is CVE-2026-66394?
SiYuan before v3.7.3 contains stored and reflected XSS vulnerabilities in SVG sanitization. Authenticated attackers can bypass the HTML parser-based cleaner by hiding scripts within desc, style, or noscript elements. Users should upgrade to v3.7.3 or later.
Azərbaycanca: SiYuan v3.7.3-dən əvvəlki versiyalarda SVG sanitizasiyasında saxlanılan və əks olunan XSS zəifliyi mövcuddur. Autentifikasiya olunmuş hücumçular HTML parser əsaslı təmizləyicini yan keçərək desc, style və ya noscript elementləri daxilində skriptlər gizlədə bilər. İstifadəçilər proqramı v3.7.3 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: SiYuan
FAQ2
Which versions of SiYuan are affected by the CVE-2026-66394 XSS vulnerability?
SiYuan versions before v3.7.3 are affected.
How can an attacker bypass SVG sanitization via CVE-2026-66394?
They can bypass the HTML parser-based cleaner by hiding scripts within desc, style, or noscript elements.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.