HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-66396 — SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List val...

·Source: NIST NVD

Updated:

Executive Summary

SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation. Attackers with editor permissions can inject onload handlers that execute arbitrary code in the Electron renderer with full Node.js access when victims open affected documents.

Analysis

SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation. Attackers with editor permissions can inject onload handlers that execute arbitrary code in the Electron renderer with full Node.js access when victims open affected documents. CVSS Score: 8.4. Published: 2026-07-27T16:18:12.220.

Indicators of Compromise (1)

CVE (1)
CVE-2026-66396
Source Attribution

Originally published by NIST NVD on Jul 27, 2026. Verified by: NIST.

Related Threats

CRITICALVulnerabilityNEW

NVD CRITICAL: CVE-2026-68579 — FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the W...

FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a fixed-size buffer of cb bytes, CliprdrStream_Read requests file contents from the RDP server and then copies the response into the caller's buffer using the serv

CVE-2026-68579
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-8457 — The WooCommerce - Social Login plugin for WordPress is vulnerable to Authenticat...

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple's public keys or validating the issuer, audience, or expiry claims, combined with the security nonce r

CVE-2026-8457
NIST NVD
MEDIUMVulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

The Hacker News