What is CVE-2026-66395?
This is a reflected XSS vulnerability in SiYuan desktop versions before 3.7.2, exploitable via crafted siyuan:// deep links in the bazaar plugin's readme handler. It allows arbitrary code execution through HTML payloads injected via the plugin name parameter. Users should update to version 3.7.2 or later immediately.
Azərbaycanca: Bu boşluq SiYuan qeydiyyat masasının 3.7.2 versiyasından əvvəlki versiyalarında aşkarlanmış reflected XSS zəifliyidir. Zərərli siyuan:// dərin keçidləri vasitəsilə bazaar plaqininin readme işləyicisində ixtiyari kod icrasına imkan verir. İstifadəçilərə dərhal 3.7.2 və ya daha yeni versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of SiYuan desktop are affected by CVE-2026-66395?
This reflected XSS vulnerability affects all versions of SiYuan desktop before 3.7.2.
How can I protect myself from CVE-2026-66395?
Users are advised to update SiYuan desktop to version 3.7.2 or later immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.