Impact
SiYuan versions before 3.7.4 lack validation between the packageName supplied during a bazaar install and the actual package content, a flaw classified as CWE-345. This oversight allows attackers who have same‑origin access to supply a mismatched packageName and repoURL, overwriting a trusted plugin. The result is persistence of the malicious plugin across application restarts, potentially enabling further unauthorized actions or data exfiltration.
Affected Systems
The vulnerability affects the SiYuan note application developed by Siyuan Note Corp, specifically all releases earlier than version 3.7.4. Systems running these earlier versions are vulnerable regardless of other configurations.
Risk and Exploitability
The CVSS score is 5.9, indicating medium impact. EPSS data is not available, so exploitation probability cannot be quantified, but the vulnerability is not listed in the CISA KEV catalog. Attackers must have same‑origin access, which could arise from compromise of the host environment or local privilege escalation, and can exploit the flaw to inject a malicious plugin that persists after restarts. The risk is moderate to high for installations that expose the bazaar install endpoint to untrusted input.
OpenCVE Enrichment