SiYuan before 3.8.4 Cross-Site Scripting via Bookmark Labels
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.6epss 0.5%
exploitation probability
0.5%top 57% of all CVEs
observed exploitation
nono source reports it
SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock tree. Attackers can craft malicious .sy notebook files with unescaped HTML in bookmark attributes that execute scripts in the Electron renderer with access to child_process for command execution.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
siyuan-note · siyuanReferences
https://github.com/siyuan-note/siyuanhttps://github.com/siyuan-note/siyuan/blob/v3.8.3/app/src/util/Tree.ts#L134https://github.com/siyuan-note/siyuan/commit/6f093ebe50afc503e2a8b056164293054f8509e7https://github.com/siyuan-note/siyuan/security/advisories/GHSA-jhfc-9mcq-8p8vhttps://www.vulncheck.com/advisories/siyuan-before-3.8.4-cross-site-scripting-via-bookmark-labels