Impact
SiYuan before version 3.8.2 contains a stored cross‑site scripting flaw located in the asset preview function. The application does not escape indexed asset content before injecting it into the DOM with innerHTML, allowing an attacker to embed arbitrary JavaScript. When a victim previews such a crafted asset, the script executes in the context of the SiYuan origin, enabling the attacker to make authenticated API calls and manipulate the workspace. This flaw can compromise the confidentiality, integrity, and availability of data within the affected workspace.
Affected Systems
The vulnerability applies to the Siyuan note product developed by siyuan-note. Any installation running a version earlier than 3.8.2 is affected. Identified by the vendor/product name siyuan-note:siyuan.
Risk and Exploitability
The CVSS score of 8.4 indicates a high‑severity high‑impact vulnerability. Although EPSS data is not available, the possession of a stored XSS on a user interface that can be triggered by an authenticated user makes exploitation likely if the attacker can add malicious assets. The issue is not listed in CISA's KEV catalog, but the potential for high privilege compromise warrants prompt remediation. Exploitation requires the attacker to place a crafted asset in a workspace; otherwise, the flaw remains unexploited.
OpenCVE Enrichment