Impact
This vulnerability is a cross‑site scripting flaw that occurs when the application inserts a user‑supplied filename into the editor’s HTML without escaping. An attacker can craft a filename containing a script that runs in the victim’s browser context. Because the script can invoke OS commands through the application’s APIs, the attacker can obtain full command‑line access, effectively executing arbitrary code on the host system.
Affected Systems
The defect affects SiYuan note prior to v3.7.4. Users running any copy of the SiYuan note client before this version are vulnerable to the flaw, regardless of whether the client is running on Windows, macOS, or Linux.
Risk and Exploitability
The CVSS base score of 9.3 indicates a high‑severity vulnerability, and although the EPSS score is not available, the lack of a KEV listing suggests no known widespread exploitation yet. The attack can be carried out by anyone who can deliver a maliciously named file to the target, for example via drag‑and‑drop or copy‑paste into the editor. Successful exploitation would lead to remote code execution with the privileges of the user running the application.
OpenCVE Enrichment