{"id":"CVE-2026-25647","summary":"Lute has a Stored Cross-Site Scripting (XSS) via Markdown hyperlink","details":"Lute is a structured Markdown engine supporting Go and JavaScript. Lute 1.7.6 and earlier (as used in SiYuan before) has a Stored Cross-Site Scripting (XSS) vulnerability in the Markdown rendering engine. An attacker can inject malicious JavaScript into a Markdown text/note. When another user clicks the rendered content, the script executes in the context of their session.","aliases":["GHSA-rw25-98wq-76qv"],"modified":"2026-08-12T03:51:41.872442604Z","published":"2026-02-06T19:03:36.847Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25647.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25647.json"},{"type":"ADVISORY","url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-rw25-98wq-76qv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25647"},{"type":"FIX","url":"https://github.com/88250/lute/commit/0118e218916cf0cc7df639b50ce74e0c6c3d1868"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/88250/lute","events":[{"introduced":"0"},{"fixed":"0118e218916cf0cc7df639b50ce74e0c6c3d1868"}],"database_specific":{"source":"REFERENCES"}},{"type":"GIT","repo":"https://github.com/siyuan-note/siyuan","events":[{"introduced":"d5d10dd41b0c9090adc63062c77185e711d59030"},{"fixed":"1ad1f14c7af8869eb8206701cbde3f8e12d0b5af"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"3.5.5"},{"introduced":"3.5.4-NA"},{"last_affected":"3.5.4-NA"}],"source":["AFFECTED_FIELD","CPE_STRING"],"cpe":"cpe:2.3:a:b3log:siyuan:3.5.4:-:*:*:*:*:*:*"}}],"versions":["3.5.4-NA","v3.5.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25647.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"}]}