Impact
SiYuan versions prior to 3.8.4 do not escape bookmark labels that are imported from external notebook files, allowing an attacker to embed malicious HTML or JavaScript in a bookmark’s attributes. When the application renders the dock tree, the unescaped code runs in the Electron renderer process. Because Electron grants the renderer access to Node.js modules, including child_process, the injected script can launch arbitrary commands, effectively giving the attacker full control over the compromised machine.
Affected Systems
All installations of SiYuan for which the version is older than 3.8.4 are affected. The vulnerability specifically targets the bookmark label rendering logic in the dock tree component; older notebooks that have already been imported into a patched version remain vulnerable if the application continues to display them without proper sanitization.
Risk and Exploitability
The CVSS score of 8.6 classifies this flaw as high severity. No EPSS score is available, but the vulnerability is not listed in CISA KEV, indicating it has not yet been widely exploited. The attack requires an attacker to supply a malicious notebook file, which can be achieved by sending a forged file to a user or compromising a trusted collaborator. Once the notebook is opened, the crafted code executes as the user, enabling full system compromise via command execution.
OpenCVE Enrichment