Skip to main content
HIGH

CVE-2026-93922

CVSS v3

8.8

HIGH

EPSS Score

0.8 %

exploit probability, as of 2026-09-29

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaScript with Node.js access when the picker opens, enabling operating system command execution.

Technical details

Published
2026-09-19
Last Modified
2026-09-19

Frequently asked questions

What is CVE-2026-93922?

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaScript with Node.js access when the picker opens, enabling operating system command execution.

Is CVE-2026-93922 actively exploited?

Active exploitation of CVE-2026-93922 has not been confirmed. Its EPSS score was 0.8% on 2026-09-29, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-93922?

CVE-2026-93922 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2026-93922 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key