Feed/CVE-2026-62204
CVE-2026-62204MEDIUMCVSS 6.6

CVE-2026-62204

Published Aug 22, 2026·Updated Aug 22, 2026

NVD Description

SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with same-origin access can overwrite existing trusted plugins by supplying mismatched packageName and repoURL parameters, achieving persistence across application restarts.

CVSS Vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free