SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autocomplete hint popup. In genHintItemHTML() (app/src/protyle/hint/extend.ts), a candidate block's name…
High CVSS 8.6
Summary
SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autocomplete hint popup. In genHintItemHTML() (app/src/protyle/hint/extend.ts), a candidate block's name, alias, and memo fields are concatenated into the popup's HTML without escaping. An attacker who can set these metadata fields on a block can inject a self-firing payload (e.g. <img src=x onerror=...>) that executes automatically when a victim types '((' followed by a search term that surfaces the …
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-5prr-vgxq-69g9
- https://www.vulncheck.com/advisories/siyuan-xss-to-rce-via-unescaped-block-metadata-in-hint-popup
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-5prr-vgxq-69g9
Timeline
- nvd_ingest NVD