Product
A reflected cross-site scripting (XSS) vulnerability exists in SiYuan desktop applications before version 3.7.2, specifically within the bazaar plugin readme handler, allowing attackers to execute arbitrary code by crafting a malicious 'siyuan://' deep link, which leads to Remote Code Execution (RCE) with full Node.js access due to insecure Electron renderer configuration.