Plugin Overwrite Vulnerability in SiYuan Versions Prior to 3.7.4
CVE-2026-62204

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
22 August 2026

What is CVE-2026-62204?

SiYuan versions before 3.7.4 contain a vulnerability where the application does not adequately validate that the packageName corresponds to the downloaded package content during bazaar install operations. This flaw allows attackers with same-origin access to manipulate installation parameters, enabling them to overwrite existing trusted plugins. This results in a risk of persistent malicious modifications even after the application restarts, underscoring the importance of secure input validation and stringent integrity checks.

Affected Version(s)

siyuan 0 < 3.7.4

siyuan 3.7.4

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

alham-rizvi
.