CVE-2026-65606 | siyuan-note SiYuan up to 3.7.1 Protocol app/src/layout/Tab.ts innerHTML icon cross site scripting
A vulnerability, which was classified as problematic, has been found in siyuan-note SiYuan up to 3.7.1. The impacted element is the function innerHTML of the file app/src/layout/Tab.ts of the component Protocol Handler. The manipulation of the argument icon leads to cross site scripting.
This vulnerability is referenced as CVE-2026-65606. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More