{"id":"CVE-2024-2692","summary":"SiYuan 3.0.3 - RCE via Server Side XSS","details":"SiYuan version 3.0.3 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to Server Side XSS.","modified":"2026-08-12T03:51:17.144073519Z","published":"2024-04-04T01:26:58.240Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/2xxx/CVE-2024-2692.json","cna_assigner":"Fluid Attacks","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/siyuan-note/siyuan/"},{"type":"ADVISORY","url":"https://fluidattacks.com/advisories/dezco/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/2xxx/CVE-2024-2692.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-2692"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/siyuan-note/siyuan","events":[{"introduced":"95764092ecea75d0c6e7c8e59839d7bec9d5b2f0"},{"last_affected":"95764092ecea75d0c6e7c8e59839d7bec9d5b2f0"}],"database_specific":{"source":["AFFECTED_FIELD","CPE_STRING"],"cpe":"cpe:2.3:a:b3log:siyuan:3.0.3:-:*:*:*:*:*:*","extracted_events":[{"introduced":"3.0.3"},{"last_affected":"3.0.3"},{"introduced":"3.0.3-NA"},{"last_affected":"3.0.3-NA"}]}}],"versions":["3.0.3","3.0.3-NA","v3.0.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-2692.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"}]}