THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-82649 — SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes system executables such as TASKKILL by name rather than by absolute path. Because NSIS nsExec::Exec resolves

[NVD] CVE-2026-82649 — SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes system executables such as TASKKILL by name rather than by absolute path. Because NSIS nsExec::Exec resolves

mednvdPublished 2026-08-30

CVE-2026-82649 CVSS: None Published: 2026-08-30T15:16:45.470

SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes system executables such as TASKKILL by name rather than by absolute path. Because NSIS nsExec::Exec resolves these calls using a search path that includes the instal

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82649