OSV 1.4.0 · github-reviewed · 修改于 2026-07-11 03:27
发布时间
2026-07-11 03:27
GitHub 审查时间
2026-07-11 03:27
NVD 发布时间
2026-06-25 06:16
源文件
advisories/github-reviewed/2026/07/GHSA-w7cg-whh7-xp28/GHSA-w7cg-whh7-xp28.json
renderPackageREADME in kernel/bazaar/readme.go renders a Bazaar package README from Markdown to HTML with the lute engine and SetSanitize(true). The lute sanitizer is an event-handler blocklist: allowAttr rejects only attribute names present in a fixed eventAttrs map copied from the w3schools legacy handler list.
That map omits modern event handlers. onpointerover, onpointerdown, onauxclick, onbeforetoggle, onfocusin, onanimationstart, and ontransitionend are not in the list, so the sanitizer passes them through verbatim on any tag.
The frontend assigns the rendered HTML to mdElement.innerHTML in app/src/config/bazaar.ts with no client-side DOMPurify on this path, into a normal element in the main document (no iframe, no sandbox). The kernel sends no Content-Security-Policy, X-Frame-Options, or X-Content-Type-Options header on any response, so an inline handler runs when its event fires.
The README is rendered when an Administrator opens a package in Settings → Marketplace, after the one-time marketplace trust consent. Install is not required.
Result: a third-party Bazaar package author runs JavaScript in the Administrator's authenticated SiYuan origin when the Administrator views and interacts with the package listing, and gains full control of the workspace.
siyuan-note/siyuan, <= 3.6.5 (latest release, 2026-04-21). Confirmed live-exploitable on the b3log/siyuan:v3.6.5 image; identical code on master HEAD.
Condition: the Administrator has accepted the marketplace trust consent (bazaar.trust, default false) and browses community Bazaar packages. The lute dependency pin is github.com/88250/lute v1.7.7-0.20260419134724-bb68012f231d.
Both the online browse path (getBazaarPackageREADME) and the installed-package path (getInstalledPlugin) reach the same sink.
render/sanitizer.go:225-232 (lute): allowAttr(name) returns false only when exists in the map, an attribute denylist rather than an allowlist.
(lute): is the w3schools handler list and contains no pointer, beforetoggle, focusin, animation, or transition handlers.
: builds the engine with and returns the HTML string to the caller.
: renders an untrusted remote package README; exposes it at (, ).
and : / , no DOMPurify, target is a plain div.
Kernel HTTP responses carry no CSP/X-Frame-Options/X-Content-Type-Options header (live-confirmed), so an inline handler is not blocked.
nameeventAttrsrender/sanitizer.go:235-334eventAttrskernel/bazaar/readme.go:108-118renderPackageREADMESetSanitize(true)kernel/bazaar/readme.go:48-88GetBazaarPackageREADMEkernel/api/bazaar.go/api/bazaar/getBazaarPackageREADMErouter.go:423CheckAuthapp/src/config/bazaar.ts:600:609mdElement.innerHTML = data.preferredReadme= response.data.htmlb3log/siyuan:v3.6.5 Docker, default config, access auth code set, marketplace trust accepted.
mkdir -p workspace/data/plugins/evil-plugin
cat > workspace/data/plugins/evil-plugin/plugin.json <<'JSON'
{"name":"evil-plugin","author":"x","version":"1.0.0","minAppVersion":"3.0.0",
"displayName":{"default":"Evil"},"description":{"default":"poc"},
"readme":{"default":"README.md"},"backends":["all"],"frontends":["all"]}
JSON
printf '<div onpointerover="alert(document.domain)">plugin description</div>\n' \
> workspace/data/plugins/evil-plugin/README.md
curl -s -X POST http://127.0.0.1:6806/api/bazaar/getInstalledPlugin \
-H "Authorization: Token <API-TOKEN>" -H "Content-Type: application/json" \
-d '{"frontend":"all","keyword":""}'
Response data.packages[].preferredReadme contains the handler verbatim:
<div onpointerover="alert(document.domain)">plugin description</div>
A control <img src=x onerror=...> in the same README is returned HTML-escaped and inert.
Live-verified: the rendered HTML is assigned to mdElement.innerHTML (no CSP, no sandbox) and the onpointerover handler executes alert(document.domain) in the SiYuan origin on hover. Handlers do not auto-fire on insertion; one pointer/focus/click interaction on the listing triggers them.
conf.api.token), which grants full Administrator API access.installBazaarPlugin and kernel control; the runtime image ships a shell.Jan Kahmen, turingpoint ([email protected])