PT-2026-76599 · Siyuan · Siyuan
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.7.4
Description
Stored cross-site scripting occurs because the software fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets. Authenticated attackers can upload HTML files as assets, which allows the execution of scripts with full kernel API access when the workspace owner opens the asset link.
Recommendations
Update to version 3.7.4 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan