PT-2026-73051 · Siyuan · Siyuan

·

CVE-2026-73044

·

Published

2026-08-15

·

Updated

2026-08-26

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.7.4
Description Stored cross-site scripting is possible due to a failure to validate or escape table column width values, which allows injection into style attributes. An attacker can use the 'setAttrViewColWidth' API to inject malicious payloads that break out of style attributes and insert event handlers on every table cell. This can lead to the execution of arbitrary code within the Electron renderer when Node integration is enabled.
Recommendations Update SiYuan to version 3.7.4 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73044

Affected Products

Siyuan