CVE-2026-23852

SiYuan is a personal knowledge management system. Versions prior to 3.5.4 have a stored Cross-Site Scripting (XSS) vulnerability that allows an attacker to inject arbitrary HTML attributes into the `icon` attribute of a block via the `/api/attr/setBlockAttrs` API. The payload is later rendered in the dynamic icon feature in an unsanitized context, leading to stored XSS and, in the desktop environment, potential remote code execution (RCE). This issue bypasses the previous fix for issue `#15970` (XSS → RCE via dynamic icons). Version 3.5.4 contains an updated fix.
Configurations

Configuration 1 (hide)

cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*

History

30 Jan 2026, 15:08

Type Values Removed Values Added
First Time B3log
B3log siyuan
CPE cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*
References () https://github.com/siyuan-note/siyuan/commit/0be7e1d4e0da9aac0da850b7aeb9b50ede7e5bdb - () https://github.com/siyuan-note/siyuan/commit/0be7e1d4e0da9aac0da850b7aeb9b50ede7e5bdb - Patch
References () https://github.com/siyuan-note/siyuan/security/advisories/GHSA-7c6g-g2hx-23vv - () https://github.com/siyuan-note/siyuan/security/advisories/GHSA-7c6g-g2hx-23vv - Exploit, Vendor Advisory, Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.6
CWE CWE-79

19 Jan 2026, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-19 20:15

Updated : 2026-01-30 15:08


NVD link : CVE-2026-23852

Mitre link : CVE-2026-23852

CVE.ORG link : CVE-2026-23852


JSON object : View

Products Affected

b3log

  • siyuan
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')