SiYuan 3.8.4 之前的版本存在一个安全漏洞:在反向链接面板的树形视图中,文档标题会被直接作为 HTML 渲染,且未对标记字符进行转义。攻击者可以通过重命名 API 或精心构造的笔记本设置恶意标题,从而在 Electron 渲染进程中执行脚本。由于该渲染进程拥有对 模块的访问权限,最终可实现命令执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.8.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet