SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan…
严重 CVSS 9.6
摘要
SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter that execute with full Node.js access through insertAdjacentHTML rendering in an insecurely configured Electron renderer.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-6gx2-8gcr-x83f
- https://www.vulncheck.com/advisories/siyuan-desktop-before-reflected-xss-to-rce-via-siyuan-protocol
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-6gx2-8gcr-x83f
时间线
- nvd_ingest NVD