Impact
SiYuan versions earlier than 3.8.4 render document titles as raw HTML in the backlink dock tree, failing to escape markup characters. Attackers can inject malicious code into titles through the rename API or by creating notebooks with crafted titles. When the unescaped title is rendered inside the Electron renderer, scripts execute with access to Node.js APIs, allowing the attacker to invoke child_process and run arbitrary commands. The result is a local or potentially remote remote‑code‑execution vulnerability that could compromise the system the application runs on.
Affected Systems
The vulnerability affects the SiYuan note‑taking application from the vendor Siyuan Note. All installed instances running a version prior to 3.8.4 are potentially impacted.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity exploit. The EPSS score is not available, suggesting limited publicly known exploitation, but the lack of mitigation in older releases elevates risk. The vulnerability is not listed in CISA’s KEV catalog. The likely attack path is via the rename API or by forcing the application to load a malicious notebook, which can be conducted by an attacker with access to the API or the file system. Successful exploitation would grant the attacker full command‑execution privileges within the Electron renderer process.
OpenCVE Enrichment