Impact
SiYuan versions before 3.8.2 embed notebook template paths directly into HTML input value attributes without proper attribute encoding. Attackers can craft malicious paths that break out of the value context and inject JavaScript that executes within the application’s same‑origin context, allowing the execution of arbitrary code, manipulation of application state, and the ability to perform same‑origin API requests.
Affected Systems
All installations of the SiYuan note application that run a version earlier than 3.8.2 are affected. The vulnerability applies to any user who can influence or create a notebook template path that is persisted in the configuration.
Risk and Exploitability
The CVSS score of 8.4 denotes a high‑severity flaw. EPSS is not available, so the precise likelihood of exploitation remains uncertain, and the vulnerability is not listed in the CISA KEV catalog. The attack requires a victim to open a notebook whose configuration contains a malicious template path; the ability to inject such a path suggests a moderate opportunistic risk in environments where notebook configurations can be influenced by external parties.
OpenCVE Enrichment