CVE-2026-62204 | siyuan-note SiYuan up to 3.7.3 Bazaar Install packageName/repoURL cross-domain policy
A vulnerability classified as problematic has been found in siyuan-note SiYuan up to 3.7.3. The affected element is an unknown function of the component Bazaar Install. Performing a manipulation of the argument packageName/repoURL results in permissive cross-domain policy with untrusted domains.
This vulnerability was named CVE-2026-62204. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More