GHSA-qh5w-p4pr-mhpjCriticalCVSS 9.0
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji...
🔗 CVE IDs covered (1)
📋 Description
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with Node integration enabled, achieving arbitrary code execution on the host system.