Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jwj6-pgg9-m3v5

Опубликовано: 18 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 8.6

Описание

SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to escape filenames before inserting them into HTML via insertAdjacentHTML. Attackers can craft a malicious filename containing script payloads that execute with full OS command access when a user drags, drops, or pastes the file into the editor.

SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to escape filenames before inserting them into HTML via insertAdjacentHTML. Attackers can craft a malicious filename containing script payloads that execute with full OS command access when a user drags, drops, or pastes the file into the editor.

EPSS

Процентиль: 4%
0.00147
Низкий

9.3 Critical

CVSS4

8.6 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.6
nvd
29 дней назад

SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to escape filenames before inserting them into HTML via insertAdjacentHTML. Attackers can craft a malicious filename containing script payloads that execute with full OS command access when a user drags, drops, or pastes the file into the editor.

EPSS

Процентиль: 4%
0.00147
Низкий

9.3 Critical

CVSS4

8.6 High

CVSS3

Дефекты

CWE-79