Impact
A reflected cross–site scripting flaw exists in the bazaar plugin readme handler of SiYuan Desktop versions earlier than 3.7.2. An attacker can supply a specially crafted siyuan:// deep link that embeds malicious HTML in the plugin name parameter. When a user opens the link, the Electron renderer executes the payload via insertAdjacentHTML, granting full Node.js privileges and allowing arbitrary code execution. The vulnerability is classified as CWE–79 and permits remote exploitation without authentication.
Affected Systems
The flaw affects the SiYuan Desktop application developed by siyuan-note. All releases prior to version 3.7.2 are vulnerable; the issue resides in the bazaar plugin bundled with the product. No specific operating system mention is given, so any platform where the desktop client runs is at risk.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. The EPSS score of < 1% indicates a very low probability of exploitation, although the KEV listing is not present, suggesting no known exploitation yet. Attackers only need to entice a user to open a crafted siyuan:// link; no additional privileges are required. Once executed, the code runs with full application‑level privileges, creating a substantial risk for confidentiality, integrity, and availability.
OpenCVE Enrichment