Impact
SiYuan versions prior to 3.7.4 contain a cross‑site scripting flaw in the unicode2Emoji function. The function fails to sanitize certain codepoint branch outputs, allowing an attacker to embed hex‑encoded markup within document icons. When the renderer has Node integration enabled, that markup is executed in the host process, resulting in arbitrary code execution on the user’s machine.
Affected Systems
Affected by product SiYuan, vendor siyuan‑note. All releases before version 3.7.4 are vulnerable.
Risk and Exploitability
The vulnerability receives a CVSS score of 9.4, indicating critical severity, but EPSS information is not available and it is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a specially crafted document icon to a user running SiYuan with Node integration enabled. Once such a document is rendered, the attacker can execute arbitrary code on the host system.
OpenCVE Enrichment