CVE-2026-62204

Severity CVSS v4.0:
MEDIUM
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
22/08/2026
Last modified:
22/08/2026

Description

SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with same-origin access can overwrite existing trusted plugins by supplying mismatched packageName and repoURL parameters, achieving persistence across application restarts.