Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gxwj-6x5p-v77c

Опубликовано: 09 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.4
CVSS3: 7.3

Описание

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the search asset preview feature that fails to escape indexed asset content before inserting it into the DOM using innerHTML. Attackers who can place crafted text assets in a workspace can execute JavaScript in the SiYuan origin when victims preview the assets, enabling authenticated API requests and workspace manipulation.

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the search asset preview feature that fails to escape indexed asset content before inserting it into the DOM using innerHTML. Attackers who can place crafted text assets in a workspace can execute JavaScript in the SiYuan origin when victims preview the assets, enabling authenticated API requests and workspace manipulation.

EPSS

Процентиль: 11%
0.00207
Низкий

8.4 High

CVSS4

7.3 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.3
nvd
15 дней назад

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the search asset preview feature that fails to escape indexed asset content before inserting it into the DOM using innerHTML. Attackers who can place crafted text assets in a workspace can execute JavaScript in the SiYuan origin when victims preview the assets, enabling authenticated API requests and workspace manipulation.

EPSS

Процентиль: 11%
0.00207
Низкий

8.4 High

CVSS4

7.3 High

CVSS3

Дефекты

CWE-79