PT-2026-79545 · Siyuan · Siyuan
CVSS v3.1
6.6
Medium
| Vector | AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.7.4
Description
Insufficient validation occurs in the bazaar install endpoints when verifying if the
packageName matches the downloaded package content. Attackers with same-origin access can overwrite trusted plugins by providing mismatched packageName and repoURL parameters, allowing them to maintain persistence across application restarts.Recommendations
Update to version 3.7.4 or later.
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan