HIGHVulnerability

CVE-2026-82653

SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with HTML/script payloads in the name field that execute in users' browsers when uninstalling packages or unlocking encrypted notebooks.

Properties

severity
HIGH
score
8.9
epss_score
0.00223
cve_id
CVE-2026-82653
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
published_at
2026-08-30T15:16:46.033
last_modified
2026-09-02T16:17:26.503
epss_percentile
0.12849

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82653 — Ninja Signal Threat Intelligence | Ninja Signal