PT-2026-99310 · Siyuan · Siyuan
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.8.4
Description
Insufficient HTML-escaping of the
data-subtype attribute occurs when generating gutter-button markup from plain-text Markdown containing a Kramdown inline attribute list (IAL). The Lute renderer parses Kramdown IAL from text/plain input, allowing an attacker to use entity-encoded quotes in data-subtype to break out of the attribute value. This enables the injection of additional attributes, such as autofocus and onfocus. When the affected gutter control receives focus, the injected handler executes. In the Electron desktop application, where the main BrowserWindow enables Node integration and disables context isolation, this leads to remote code execution with renderer Node.js privileges.Recommendations
Update to version 3.8.4.
Exploit
Fix
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan