Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-56397

Опубликовано: 21 июн. 2026
Источник: nvd
CVSS3: 9.6
EPSS Низкий

Описание

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands.

EPSS

Процентиль: 49%
0.007
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 9.6
github
около 1 месяца назад

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands.

EPSS

Процентиль: 49%
0.007
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-79