SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escap…
Critical CVSS 9.6
Summary
SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied when HasUnclosedHtmlTag returns true; because balanced self-closing tags such as <img> are skipped by that check, a payload like <img src=x onerror=...> is stored unescaped and later inserted into the page via innerHTML, executing when the database is viewed. Beca…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/siyuan-note/siyuan/commit/41f2861c87575ff5ac4b50a0520b1a4fe55b4a70
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-pw5c-qhf3-jhwh
- https://www.vulncheck.com/advisories/siyuan-before-stored-xss-to-rce-via-attribute-view
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-pw5c-qhf3-jhwh
Timeline
- nvd_ingest NVD