Impact
The flaw is a missing validation on the packageName parameter in the Bazaar install and uninstall endpoints. A crafted directory traversal sequence allows an authenticated administrator to write arbitrary files to any location or delete arbitrary directories, a classic path‑traversal weakness (CWE-22).
Affected Systems
SiYuan note, versions prior to 3.7.4, are affected. Administrators with full privileges can exploit the flaw by invoking the install or uninstall functionality with a malicious packageName value.
Risk and Exploitability
The vulnerability scores a CVSS of 9.4, indicating critical severity. Although the EPSS score is not available, exploitation requires only administrator authentication, which is a high‑privilege level. The flaw is not listed in CISA’s KEV catalog yet, but once the requisite privilege is obtained, an attacker can write files anywhere or remove directories, posing significant confidentiality, integrity, and availability risks.
OpenCVE Enrichment