Report: Update: CVE-2026-40322 - SiYuan: Mermaid `javascript:` Link Injection Leads to Stored XSS and Electron RCE

Report: Update: CVE-2026-40322 - SiYuan: Mermaid `javascript:` Link Injection Leads to Stored XSS and Electron RCE

CVE ID :CVE-2026-40322 Published : April 16, 2026, 11:16 p.m. | 1 hour, 52 minutes ago Description :SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendered with securityLevel set to

CVE Details

Published
April 16, 2026