SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with same-origin access can overwrite existing trusted pl…
Medium CVSS 6.6
Summary
SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with same-origin access can overwrite existing trusted plugins by supplying mismatched packageName and repoURL parameters, achieving persistence across application restarts.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-rpx2-p6hp-x5gj
- https://www.vulncheck.com/advisories/siyuan-before-plugin-overwrite-via-bazaar-install
Timeline
- nvd_ingest NVD