Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-62204

MEDIUM NVD
CVSS Score 6.6
Severity MEDIUM
Published Aug 22, 2026
Vendor unknown

Description

SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with same-origin access can overwrite existing trusted plugins by supplying mismatched packageName and repoURL parameters, achieving persistence across application restarts.

References