SiYuan versions before v3.8.2 are affected by a stored cross-site scripting (XSS) vulnerability in the asset serving component. The vulnerability stems from an incomplete file extension blocklist that fails to block script-capable file types such as .xht, .ehtml, .xsl, .xbl, and .rdf. Attackers who can upload files to a SiYuan instance can exploit this flaw to serve files that browsers interpret as executable media types and run JavaScript. Successful exploitation can lead to theft of API tokens and full compromise of affected workspaces. The issue has been patched in SiYuan v3.8.2. Users are advised to upgrade immediately to mitigate the risk.