CVE-2026-62204
🔶 mediumSummary
SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with same-origin access can overwrite existing trusted plugins by supplying mismatched packageName and repoURL parameters, achieving persistence across application restarts.
CVSS Score
6.6
Medium
EPSS Score
0.1
Exploit Probability
Published Date
2026-08-22
First Seen: 2026-08-23
📊 Relative Risk Intelligence
This CVE is Lower Risk - more severe than 47.1% of all 348,756 vulnerabilities in our database.
#184,640
Below average severity
Severity Percentile
Last Modified
2026-08-22
Source
NVD 🔗
CVSS Vector 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L
CVSS Vector 4.0
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE IDs (Weakness Types)