Impact
SiYuan versions prior to 3.8.1 contain a stored cross‑site scripting flaw in confirmDialog(). The application directly inserts unescaped package and notebook names into innerHTML when rendering confirmation dialogs. An attacker can craft a bazaar package whose name includes malicious JavaScript or HTML and trick a user into installing, uninstalling, or unlocking the package, causing the payload to execute in the victim’s browser. This allows arbitrary client‑side code execution, enabling cookie theft, session hijacking, and defacement in the user’s context.
Affected Systems
The flaw affects any SiYuan installation built with the Siyuan Note "siyuan" product that is version 3.x but lower than 3.8.1. It is not tied to specific operating systems; the vulnerability resides in the main application logic. Users of any 3.x release older than 3.8.1, whether running on Windows, macOS, or Linux, are potentially affected. No specific version sub‑numbers are listed, so all releases preceding 3.8.1 are covered.
Risk and Exploitability
The baseline CVSS score of 9.3 rates the issue as critical, indicating a high impact on confidentiality, integrity, and availability if exploited. The EPSS score is not provided, so the quantified likelihood cannot be determined, but exploitation requires only that a victim interacts with a maliciously named package or notebook. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog, meaning no public proofs of exploitation have been disclosed yet, but the high severity warrants careful monitoring.
OpenCVE Enrichment