思源笔记(SiYuan)在 v3.7.4 之前的版本中,在安装端点(bazaar install endpoints)存在未对 packageName 与下载的实际包内容进行有效性校验的安全漏洞。具有同源访问权限的攻击者可以通过提供不匹配的 packageName 和 repoURL 参数,覆盖已有的受信任插件,从而实现在应用重启后保持持久化控制。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| siyuan-note | siyuan | < 3.7.4 |
affected |
3.7.4 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.7.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-60084 | 8.7 HIGH | SiYuan before v3.7.4 Arbitrary File Deletion via removeTemplate |
| CVE-2026-60083 | 4.9 MEDIUM | SiYuan before v3.8.0 Incomplete Path Blocklist via MCP file tool |
| CVE-2026-59809 | 4.9 MEDIUM | SiYuan before v3.8.0 Secret Exfiltration via http_request URL |
No comments yet