Impact
SiYuan before version 3.7.2 does not properly escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images. This allows a stored cross‑site scripting vulnerability, where an attacker with editor permissions can inject an onload handler into the style attribute that runs arbitrary code with full Node.js access when a victim opens the affected document.
Affected Systems
The vulnerability affects the SiYuan note application before version 3.7.2. Users with editor privileges can embed malicious code; any user who later opens the affected document will be exposed.
Risk and Exploitability
The CVSS score of 9.3 marks this flaw as critical. The EPSS score of 0.00296 indicates a very low but non‑zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploit requires the attacker to edit a document with editor permissions, embed a malicious onload handler into the title‑img value, and ensure a victim opens the document in the Electron renderer. Because the attacker gains full Node.js privileges, successful exploitation results in complete loss of confidentiality, integrity, and availability for the affected system.
OpenCVE Enrichment