PT-2026-84676 · Siyuan · Siyuan
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.8.2
Description
Stored cross-site scripting occurs in asset serving because the extension blocklist is incomplete and fails to include script-capable file types. This allows attackers to upload files with extensions such as
.xht, .ehtml, .xsl, .xbl, or .rdf that resolve to executable media types. Consequently, JavaScript can be executed to steal API tokens and compromise workspaces.Recommendations
Update to version 3.8.2 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan