SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim opens the Gal…
Critical CVSS 9.0
Summary
SiYuan is a personal knowledge management system. Prior to version 3.6.2, an attacker who can place a malicious URL in an Attribute View mAsse field can trigger stored XSS when a victim opens the Gallery or Kanban view with “Cover From -> Asset Field” enabled. The vulnerable code accepts arbitrary http(s) URLs without extensions as images, stores the attacker-controlled string in coverURL, and injects it directly into an <img src="..."> attribute without escaping. In the Electron desktop client…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/siyuan-note/siyuan/issues/17246 Issue Tracking
- https://github.com/siyuan-note/siyuan/releases/tag/v3.6.2 Release Notes
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-rx4h-526q-4458 Exploit
Timeline
- nvd_ingest NVD