THREAT OPS › Threat News › [NVD] CVE-2026-82653 (HIGH 8.9) — SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with HTML/script payloads in the name
[NVD] CVE-2026-82653 (HIGH 8.9) — SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with HTML/script payloads in the name
CVE-2026-82653 CVSS: 8.9 HIGH Published: 2026-08-30T15:16:46.033
SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with HTML/script payloads in the name field that execute in users' browsers when uninstalli
Indicators of compromise
- CVE-2026-82653cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82653