Impact
SiYuan versions up to 3.8.4 render notebook names as raw HTML in the Daily Note picker dialog. An attacker can create a notebook whose name contains JavaScript that is executed when the picker opens, giving the script Node.js access within the Electron context. This flaw allows the attacker to run arbitrary operating system commands on the host machine, effectively achieving remote code execution. The vulnerability is a stored cross‑site scripting flaw (CWE‑79).
Affected Systems
The affected product is SiYuan Note (product name 'siyuan') from the vendor b3log. All releases up to and including version 3.8.4 are impacted. No other vendors or products are explicitly listed as affected.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. The EPSS score is unavailable and the CVE is not listed in CISA’s KEV catalog, so public exploitation data is scarce. The attack vector is inferred to require the victim to open the Daily Note picker after a malicious notebook has been created, which can be performed by a local user or by any user who opens the application containing the vulnerable notebook. Because the payload runs with Node.js privileges, a single successful exploitation can lead to full system compromise. The risk remains significant until a fix is applied.
OpenCVE Enrichment