PT-2026-73050 · Siyuan · Siyuan
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.7.4
Description
A remote code execution issue exists in the Template calculation operator. The software renders user-authored Go templates and stores the output without sanitization. This allows attackers to inject malicious HTML and JavaScript into template calculations. When the database is opened, these scripts execute in the desktop client renderer with Node integration enabled, leading to arbitrary code execution.
Recommendations
Update SiYuan to version 3.7.4 or later.
Fix
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan