CVE-2026-62204 MEDIUM

CVE-2026-62204: SiYuan before v3.7.4 Plugin Overwrite via Bazaar Install

Vendor Siyuan-Note
Product siyuan
Weakness CWE-345
Published August 22, 2026
Last update August 26, 2026

CVSS base score

5.9/10
Attack vector Local
Attack complexity High
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L

What the vulnerability does

01Description

SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with same-origin access can overwrite existing trusted plugins by supplying mismatched packageName and repoURL parameters, achieving persistence across application restarts.

Key dates

02Disclosure timeline

August 22, 2026 CVE published
August 26, 2026 Record updated

Related vulnerabilities

04Related CVE