CVE-2026-62204

MEDIUM CVSS 4.0: 5.9 EPSS 0.07%
Updated Aug 22, 2026
B3Log
Parameter Value
CVSS 5.9 (MEDIUM)
Affected Versions before 3.7.4
Fixed In 3.7.4
Type CWE-345 (Insufficient Verification of Data)
Vendor B3Log
Public PoC No

SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with same-origin access can overwrite existing trusted plugins by supplying mismatched packageName and repoURL parameters, achieving persistence across application restarts.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
High
Difficult to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
Low
Basic privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
High
Complete data modification
Availability
Low
Partial disruption

CVSS Vector v4.0

Vulnerable Products 1

Configuration From (including) Up to (excluding)
B3log Siyuan
cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*
3.7.4