SiYuan Bazaar marketplace renders unescaped package name and version metadata, allowing stored XSS and Electron code execution in github.com/siyuan-note/siyuan/kernel
{
"review_status": "UNREVIEWED",
"url": "https://pkg.go.dev/vuln/GO-2026-5001"
}