CVE-2026-87812
Deferred Deferred - Pending Action

Stored XSS in SiYuan Bazaar Package Cards

Vulnerability report for CVE-2026-87812, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: VulnCheck

Description

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in Bazaar package cards where the iconURL metadata is inserted directly into HTML img src attributes without escaping. Attackers can inject malicious URLs with event handlers that execute JavaScript in the authenticated SiYuan origin when users view Bazaar listings, enabling API requests and application state manipulation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
siyuan siyuan to 3.8.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in SiYuan versions before v3.8.2. It occurs in the Bazaar package cards feature where the iconURL metadata is inserted directly into HTML img src attributes without proper escaping. Attackers can inject malicious URLs containing JavaScript event handlers that execute when users view Bazaar listings.

Detection Guidance

To detect this vulnerability, inspect SiYuan installations for versions before 3.8.2. Check Bazaar package cards for malicious iconURL values containing JavaScript event handlers like onerror. Review network traffic for unusual API requests from SiYuan clients.

Impact Analysis

An attacker could execute arbitrary JavaScript in your authenticated SiYuan session when you view a compromised Bazaar listing. This could allow them to make API requests and manipulate the application state, potentially stealing data or performing unauthorized actions on your behalf.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating confidentiality requirements in GDPR and HIPAA. It may result in data breaches exposing personal or health information, potentially leading to regulatory penalties and compliance violations.

Mitigation Strategies

Upgrade SiYuan to version 3.8.2 or later. Validate and sanitize iconURL inputs by escaping special characters. Implement a URL allowlist for image sources. Monitor Bazaar listings for suspicious payloads.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87812. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart