What is CVE-2026-66396?
A stored cross-site scripting (XSS) vulnerability has been identified in SiYuan note-taking software. In versions prior to 3.7.2, the title-img Individual Attribute List value is not properly escaped when rendering Gallery and Kanban cover images, allowing attackers with editor permissions to inject onload handlers and execute arbitrary code via unescaped style attribute interpolation. Immediate update to version 3.7.2 or later is required.
Azərbaycanca: SiYuan qeyd proqramında saxlanılan XSS zəifliyi aşkarlanıb. 3.7.2-dən əvvəlki versiyalarda Galereya və Kanban üzlük şəkillərinin göstərilməsi zamanı title-img atributunun düzgün escap edilməməsi səbəbindən redaktor icazəsi olan hücumçu `onload` hadisə işlədiciləri vasitəsilə ixtiyari kod icra edə bilər. Proqram dərhal ən az 3.7.2 versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
In which SiYuan features can CVE-2026-66396 be exploited?
The vulnerability occurs when rendering Gallery and Kanban cover images due to improper escaping of the title-img attribute.
What version of SiYuan should be installed to mitigate CVE-2026-66396?
Immediate update to version 3.7.2 or later is required.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.