PT-2026-73048 · Siyuan · Siyuan

·

CVE-2026-73041

·

Published

2026-08-15

·

Updated

2026-08-27

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.7.4
Description Insufficient validation or escaping of annotation fields written to disk via the 'setFileAnnotation' endpoint allows attackers to inject malicious markup. This markup executes as a script within the PDF renderer, granting full Node.js access when a user opens an annotated PDF.
Recommendations Update to version 3.7.4 or later.

Exploit

Fix

RCE

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73041

Affected Products

Siyuan