← All CVEs

CVE-2026-50551

critical · 9.9

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in the Attribute View (database) asset cell renderer that escalates to remote code execution (RCE) in the Electron desktop client. This vulnerability is fixed in 3.7.0.

9.9
CVSS
0.8%
EPSS (exploit prob.)
54th
EPSS percentile
2026-06-24
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-79

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-50551