Impact
SiYuan before version 3.8.2 stores user‑supplied iconURL values directly into HTML img tags without escaping, allowing attackers who can create or upload Bazaar packages to inject malicious URLs that trigger JavaScript when other users view the listings. This stored cross‑site scripting enables the execution of scripts in the authenticated user’s browser context, permitting the attacker to make API requests and manipulate application state.
Affected Systems
SiYuan Note, version earlier than 3.8.2. The affected product is Siyuan, and the vendor is Siyuan Note.
Risk and Exploitability
The CVSS score of 7.4 signals high severity. No EPSS score is available, so the exact exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path involves an attacker creating a Bazaar package with a malicious iconURL that includes an event handler such as onerror. When a legitimate user opens the Bazaar listing, the script runs under the user’s authenticated context, allowing the attacker to perform unauthorized API calls and change application state.
OpenCVE Enrichment