CVE-2026-87814
Deferred Deferred - Pending Action

Stored XSS in SiYuan Search Asset Preview

Vulnerability report for CVE-2026-87814, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-18

Assigner: VulnCheck

Description

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the search asset preview feature that fails to escape indexed asset content before inserting it into the DOM using innerHTML. Attackers who can place crafted text assets in a workspace can execute JavaScript in the SiYuan origin when victims preview the assets, enabling authenticated API requests and workspace manipulation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-18
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
siyuan siyuan to 3.8.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SiYuan before v3.8.2 has a stored cross-site scripting (XSS) vulnerability in the search asset preview feature. The app fails to escape indexed asset content before inserting it into the DOM using innerHTML. Attackers can place crafted text assets in a workspace to execute JavaScript when victims preview them, enabling authenticated API requests and workspace manipulation.

Detection Guidance

This vulnerability is specific to the SiYuan application and cannot be detected via standard network or system commands. Instead, check the SiYuan version installed on your system. If it is version 3.8.1 or earlier, the system is vulnerable. Look for suspicious JavaScript execution in the SiYuan interface when previewing assets.

Impact Analysis

This vulnerability allows attackers to execute arbitrary JavaScript in the SiYuan origin when you preview crafted assets. This could lead to unauthorized access to your workspace, manipulation of data, or execution of privileged actions through authenticated API requests.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling unauthorized access to sensitive data. The stored XSS allows attackers to execute JavaScript in the SiYuan origin, which could lead to data exfiltration, unauthorized modifications, or privilege escalation. GDPR requires protection against unauthorized data access, while HIPAA mandates safeguards for protected health information. Exploitation of this flaw could violate these requirements.

Mitigation Strategies

Upgrade SiYuan to version 3.8.2 or later immediately. If upgrading is not possible, avoid using the Search Asset Preview feature until patched. Review workspace assets for any untrusted or crafted text assets and remove suspicious content. Ensure no unauthorized changes have been made to workspace data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87814. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart