CyberRota Analysis
AI-GeneratedVersions of SiYuan prior to 3.8.4 are vulnerable to a stored cross-site scripting flaw in the gallery and kanban database renderers, allowing attackers to inject malicious JavaScript into aria-label attributes. This vulnerability can lead to the execution of arbitrary commands with user privileges in the Electron desktop app when nodeIntegration is enabled. Organizations using affected versions of SiYuan, particularly those with the Electron app configured in this manner, should prioritize remediation to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery and kanban database renderers where field descriptions are not escaped in aria-label attributes. In the Electron desktop app with nodeIntegration enabled, attackers can inject JavaScript that calls Node.js child_process APIs to execute arbitrary commands with user privileges.