GHSA-qh5w-p4pr-mhpjCriticalCVSS 9.0

SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji...

Published
August 16, 2026
Last Modified
August 16, 2026

🔗 CVE IDs covered (1)

📋 Description

SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with Node integration enabled, achieving arbitrary code execution on the host system.

🔗 References (4)