CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2026-66395

CRITICAL
9.4
CVSS Severity Score
EPSS Score0.3270%
EPSS Percentile25.13th
Published2026-07-27
Last Modified2026-07-28
Data SourcesNVDFIRST.org EPSS

Vulnerability Description

SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter that execute with full Node.js access through insertAdjacentHTML rendering in an insecurely configured Electron renderer.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

相關漏洞威脅