GHSA-65ff-h86c-m5g9CriticalCVSS 9.0

SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates...

Published
August 16, 2026
Last Modified
August 16, 2026

🔗 CVE IDs covered (1)

📋 Description

SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort menu, with Node integration enabled in the desktop client enabling code execution.

🔗 References (4)