CyberRota Analysis
AI-GeneratedVersions of SiYuan prior to 3.7.4 are vulnerable to a critical cross-site scripting flaw in the unicode2Emoji function, which does not adequately sanitize output. This vulnerability allows attackers to create malicious document icons that can execute arbitrary code on the host system when Node integration is enabled. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with Node integration enabled, achieving arbitrary code execution on the host system.