{"id":"CVE-2026-62204","title":"SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints","summary":"SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with same-origin access can overwrite existing trusted plugins by supplying mismatched packageN…","severity":"medium","cvss":6.6,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L","cwe":["CWE-345"],"published":"2026-08-22","updated":"2026-08-22","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-62204","references":[{"url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-rpx2-p6hp-x5gj","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/siyuan-before-plugin-overwrite-via-bazaar-install","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"ingestedAt":"2026-08-23T04:42:14.584Z","epss":0.00094,"epssPercentile":0.00559,"slug":"CVE-2026-62204","body":"## Overview\n\nSiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with same-origin access can overwrite existing trusted plugins by supplying mismatched packageName and repoURL parameters, achieving persistence across application restarts.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":36.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}