CRITICAL 9.6 Go

Duplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS

GHSA-24r3-p3x6-cqvx

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-v3mg-9v85-fcm7. This link is maintained to preserve external references.

Original Description

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS commands.

Ready to move

Start Securing

Free, no credit card | First findings in minutes