Security Advisory

CVE-2026-62204

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-22 12:26:41
Last updated 2026-08-22 12:26:41
Assigner VulnCheck
CVSS score 6.6
State PUBLISHED

Description

SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with same-origin access can overwrite existing trusted plugins by supplying mismatched packageName and repoURL parameters, achieving persistence across application restarts.