Impact
SiYuan versions before 3.8.4 fail to escape four stored Attribute View values placed inside textarea elements. This flaw allows an authenticated user to inject JavaScript by modifying field descriptions, template sources, select option descriptions, or footer calculation templates. When another user opens affected database menus, the injected script executes. In the Electron desktop client, when nodeIntegration is enabled, the script can be leveraged for arbitrary command execution with the privileges of the SiYuan process.
Affected Systems
Affected vendors and products include siyuan-note:siyuan. Any installation of SiYuan that is earlier than version 3.8.4 is vulnerable; no specific patch version is listed for the affected releases, but the issue is resolved in v3.8.4 and later.
Risk and Exploitability
The vulnerability can be exploited by any authenticated user with permission to modify the mentioned Attribute View values, which is typically a normal user role in many deployments. Although the EPSS score is not available, the CVSS score of 8.5 indicates a high severity. The flaw is not listed in CISA's KEV catalog, but the possibility of remote code execution in the desktop client elevates the risk for organizations using the Electron app with nodeIntegration enabled.
OpenCVE Enrichment