CVE-2026-62204
MEDIUM
NVD
CVSS Score
6.6
Severity
MEDIUM
Published
Aug 22, 2026
Vendor
unknown
Description
SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with same-origin access can overwrite existing trusted plugins by supplying mismatched packageName and repoURL parameters, achieving persistence across application restarts.