Impact
SiYuan versions prior to 3.8.2 execute code that is pasted from a specially crafted clipboard entry. The application trusts the attacker‑writable text/siyuan MIME type and skips the usual sanitization step in its paste handler. This omission allows a payload containing JavaScript to run with full Node.js privileges through the Electron main process, granting the attacker unrestricted access to the local filesystem, network, and other system resources. The weakness is a classic reflected input flaw that permits arbitrary script execution, represented by CWE‑79.
Affected Systems
The vulnerability affects the Siyuan note application from B3LOG (siyuan-note:siyuan). Users installing releases older than 3.8.2 are impacted; versions 3.8.2 and newer are not susceptible to this specific flaw.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity. An attacker does not need authentication or privileged access; they only need to create a malicious web page or manipulate the clipboard on a machine where SiYuan is installed. The EPSS score is not available, so the current exploitation probability cannot be quantified, but the flaw is technically straightforward and executable in a typical desktop environment. The vulnerability is not listed in the CISA KEV catalog at present. Based on the description, the likely attack vector is inferred from the description and involves delivering malicious clipboard content to the user, who must paste it into SiYuan.
OpenCVE Enrichment