A critical vulnerability has been identified in SiYuan, an open-source personal knowledge management system. Prior to version 3.7.0, the Attribute View (database) asset cell renderer in SiYuan contains a stored cross-site scripting (XSS) vulnerability. This flaw allows attackers to execute arbitrary code remotely through the Electron desktop client, escalating privileges and potentially compromising system integrity. The CVSS score of 9.9 reflects the high severity of this issue. All users running affected versions of SiYuan are advised to update to version 3.7.0 or later to mitigate this risk. The vulnerability is resolved in the latest release, and no workarounds are available. Organizations and individuals utilizing SiYuan should prioritize applying this update to prevent potential exploitation.
CRITICAL
CVSS 9.9
CVE-2026-50551
2026-08-22
Critical RCE Vulnerability in SiYuan (CVE-2026-50551)
SiYuan versions prior to 3.7.0 contain a critical stored XSS vulnerability leading to RCE. Attackers can exploit this to execute arbitrary code on affected systems. Users are advised to upgrade immediately.