PT-2026-73056 · Siyuan · Siyuan
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.7.4
Description
Stored Cross-Site Scripting (XSS) occurs because attribute-view field names are stored without HTML escaping and interpolated directly into option elements using
innerHTML within the sort menu. An attacker can inject markup by renaming a database field, allowing the execution of arbitrary JavaScript when a user opens the sort menu. In the desktop client, if Node integration is enabled, this can lead to remote code execution.Recommendations
Update SiYuan to version 3.7.4 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan