Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-24r3-p3x6-cqvx

Опубликовано: 21 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.4
CVSS3: 9.6

Описание

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands.

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands.

EPSS

Процентиль: 49%
0.007
Низкий

9.4 Critical

CVSS4

9.6 Critical

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 9.6
nvd
около 1 месяца назад

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands.

EPSS

Процентиль: 49%
0.007
Низкий

9.4 Critical

CVSS4

9.6 Critical

CVSS3

Дефекты

CWE-79