SiYuan prior to version 3.6.4 contains a stored cross-site scripting (XSS) vulnerability in table caption content that fails to properly escape user input before rendering into HTML. When a malicious note is synced across users in a shared workspace, the vulnerability can be exploited to achieve remote code execution in the Electron desktop client, which runs with both nodeIntegration enabled and contextIsolation disabled, allowing attacker-controlled JavaScript to access dangerous Node.js APIs. The vulnerability carries a CVSS score of 9.0 (Critical) with a network-based attack vector, low complexity, and the requirement for low privileges and user interaction. The impact is severe across confidentiality, integrity, and availability, as successful exploitation grants the attacker full code execution capabilities on the victim's system. An attacker need only craft a malicious note and wait for the victim to sync and open it. There is no evidence of active exploitation in the wild at this time, with the vulnerability absent from CISA's Known Exploited Vulnerabilities catalog and marked as inactive on public hot lists. The EPSS score of 0.00155 indicates low probability of exploitation attempts relative to the broader CVE landscape, though the critical nature of the vulnerability warrants immediate patching to version 3.6.4 or later.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.6.4CPE matchmatch criteria | cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.6 Bluesky, 0.3 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.