THREAT OPS › Threat News › [NVD] CVE-2026-82649 — SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes system executables such as TASKKILL by name rather than by absolute path. Because NSIS nsExec::Exec resolves
[NVD] CVE-2026-82649 — SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes system executables such as TASKKILL by name rather than by absolute path. Because NSIS nsExec::Exec resolves
CVE-2026-82649 CVSS: None Published: 2026-08-30T15:16:45.470
SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes system executables such as TASKKILL by name rather than by absolute path. Because NSIS nsExec::Exec resolves these calls using a search path that includes the instal
Indicators of compromise
- CVE-2026-82649cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82649