home.social

#siyuan — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #siyuan, aggregated by home.social.

fetched live
  1. CVE-2026-93923: stored XSS in SiYuan through 3.8.4, unescaped heading style attributes. Executes in Electron renderer with full system access. CVSS 8.8, no patch yet. Treat untrusted notebooks with caution. valtersit.com/cve/CVE-2026-939 #CVE #infosec #SiYuan

  2. CVE-2026-93923: stored XSS in SiYuan through 3.8.4, unescaped heading style attributes. Executes in Electron renderer with full system access. CVSS 8.8, no patch yet. Treat untrusted notebooks with caution. valtersit.com/cve/CVE-2026-939 #CVE #infosec #SiYuan

  3. CVE-2026-93922: stored XSS in SiYuan up to 3.8.4, notebook names rendered raw in Daily Note picker. JS runs in Electron with Node access - leads to OS command execution. CVSS 8.8, no patch yet. Update or restrict untrusted valtersit.com/cve/CVE-2026-939 #CVE #infosec #SiYuan

  4. CVE-2026-93922: stored XSS in SiYuan up to 3.8.4, notebook names rendered raw in Daily Note picker. JS runs in Electron with Node access - leads to OS command execution. CVSS 8.8, no patch yet. Update or restrict untrusted valtersit.com/cve/CVE-2026-939 #CVE #infosec #SiYuan