Impact
SiYuan versions before 3.7.4 ignore the Content‑Disposition and X‑Content‑Type‑Options headers when delivering user‑supplied assets. Because these safety headers are omitted, an authenticated user can upload an arbitrary HTML file as an asset; when the workspace owner clicks the asset link, the browser executes the HTML, and the embedded script gains unrestricted access to SiYuan’s kernel API. This flaw leads to full code execution within the application, allowing the attacker to modify or delete documents, exfiltrate data, or perform further actions on the host that hosts the workspace.
Affected Systems
All installations of SiYuan using the assets endpoint that are running any version earlier than 3.7.4 are vulnerable. The affected vendor is Siyuan‑Note, and the product is the Siyuan note‑taking application.
Risk and Exploitability
The CVSS score of 9.4 classifies this as a critical flaw; the EPSS score is not available but typical for insider‑or‑authenticated‑user attacks. The vulnerability is not listed in the CISA KEV catalog. An attacker must have a valid authenticated session in the target workspace, and once such a session exists, exploitation is straightforward: upload a malicious asset and wait for the owner to click it.
OpenCVE Enrichment