Impact
SiYuan before version 3.8.2 is vulnerable to a stored cross‑site scripting flaw in its asset‑serving subsystem caused by an incomplete blocklist of extension types. The flaw allows an attacker to upload files with extensions such as .xht, .ehtml, .xsl, .xbl, or .rdf that are interpreted by browsers as executable media types and can execute injected JavaScript. This JavaScript runs with the privileges of the victim’s browser session, enabling the theft of API tokens and the compromise of workspaces that rely on those tokens for authentication and data access.
Affected Systems
The vulnerability impacts all installations of SiYuan produced by the vendor siyuan-note, specifically any deployment running a version prior to 3.8.2. No patch has yet been released for older releases, and this issue has been documented for all affected versions, so administrators must verify the current upgrade status of their deployments.
Risk and Exploitability
The flaw carries a CVSS score of 8.6, indicating high severity, and the EPSS score is not available, suggesting unknown exploitation probability but not indicating that exploitation is unlikely. The vulnerability is not listed in the CISA KEV catalog. Attackers would typically send a malicious file upload request to the asset handler; once stored and accessed by a victim, the embedded script executes in the victim’s browser context, enabling token theft. The exploit is straightforward and requires no additional privileges or complex user interaction beyond normal file upload functionality, making it a high‑risk threat for organizations relying on SiYuan for sensitive workspace management.
OpenCVE Enrichment