Plugin Overwrite Vulnerability in SiYuan Versions Prior to 3.7.4
CVE-2026-62204
5.9MEDIUM
What is CVE-2026-62204?
SiYuan versions before 3.7.4 contain a vulnerability where the application does not adequately validate that the packageName corresponds to the downloaded package content during bazaar install operations. This flaw allows attackers with same-origin access to manipulate installation parameters, enabling them to overwrite existing trusted plugins. This results in a risk of persistent malicious modifications even after the application restarts, underscoring the importance of secure input validation and stringent integrity checks.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
