CVE-2026-54067 - SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
CVE ID :CVE-2026-54067 Published : June 24, 2026, 9:14 p.m. | 3 hours, 56 minutes ago Description :SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing tag when renderSnippet() interpolates it via insertAdjacentHTML. A payload like runs...