CVE-2026-23852

SiYuan is a personal knowledge management system. Versions prior to 3.5.4 have a stored Cross-Site Scripting (XSS) vulnerability that allows an attacker to inject arbitrary HTML attributes into the `icon` attribute of a block via the `/api/attr/setBlockAttrs` API. The payload is later rendered in the dynamic icon feature in an unsanitized context, leading to stored XSS and, in the desktop environment, potential remote code execution (RCE). This issue bypasses the previous fix for issue `#15970` (XSS → RCE via dynamic icons). Version 3.5.4 contains an updated fix.
CVSS

No CVSS.

Configurations

No configuration.

History

19 Jan 2026, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-19 20:15

Updated : 2026-01-26 15:05


NVD link : CVE-2026-23852

Mitre link : CVE-2026-23852

CVE.ORG link : CVE-2026-23852


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')