THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-82653 (HIGH 8.9) — SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with HTML/script payloads in the name

[NVD] CVE-2026-82653 (HIGH 8.9) — SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with HTML/script payloads in the name

mednvdPublished 2026-08-30

CVE-2026-82653 CVSS: 8.9 HIGH Published: 2026-08-30T15:16:46.033

SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with HTML/script payloads in the name field that execute in users' browsers when uninstalli

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82653