Retour à la veille

CVE-2026-62204

Publié : 22 août 2026
Modifié : 22 août 2026
Lien officiel NVD
Score CVSS
6.6
MEDIUM

Description détaillée

SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with same-origin access can overwrite existing trusted plugins by supplying mismatched packageName and repoURL parameters, achieving persistence across application restarts.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L

Références et Patchs