CVE-2026-66395 | siyuan-note SiYuan up to 3.7.1 Bazaar Plugin Readme plugin name cross site scripting
A vulnerability, which was classified as problematic, was found in siyuan-note SiYuan up to 3.7.1. This affects an unknown function of the component Bazaar Plugin Readme Handler. The manipulation of the argument plugin name results in cross site scripting.
This vulnerability is known as CVE-2026-66395. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.