CVE-2026-62204
Severity CVSS v4.0:
MEDIUM
Type:
CWE-345
Insufficient Verification of Data Authenticity
Publication date:
22/08/2026
Last modified:
22/08/2026
Description
SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with same-origin access can overwrite existing trusted plugins by supplying mismatched packageName and repoURL parameters, achieving persistence across application restarts.
Impact
Base Score 4.0
5.90
Severity 4.0
MEDIUM
Base Score 3.x
6.60
Severity 3.x
MEDIUM



