Skip to content
CVE-2026-73050 - Exploits & Severity

CVE-2026-73050 - Exploits & Severity

Feedly • August 16, 2026

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79)

SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotation marks in the color value, executing arbitrary JavaScript when viewing databases containing the malicious select field.

An authenticated user with permissions to create or modify select field options in SiYuan can inject malicious JavaScript code that executes in the browser of any user viewing the affected database, allowing them to steal session data, modify database contents, or perform actions on behalf of other users.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Update SiYuan to version 3.7.4 or later. Until patching is possible, restrict access to database design/schema modification features and avoid opening databases from untrusted sources. Review existing select field color values for suspicious code patterns.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

NVD published the first details for CVE-2026-73050

Feedly found the first article mentioning CVE-2026-73050 . See article

A CVSS base score of 9 has been assigned.

GitHub Advisories released a security advisory .

A critical stored Cross-Site Scripting (XSS) vulnerability with a CVSS score of 9 affects SiYuan versions prior to v3.7.4, allowing attackers to inject malicious JavaScript into database select options, which executes in victims' browsers. There are no public proof-of-concept exploits available, but users are advised to upgrade to version 3.7.4 or later to mitigate the issue. The vulnerability requires authenticated access to exploit, and while no specific downstream impacts on third-party vendors are mentioned, the potential for client-side attacks is significant. See article

SiYuan Kernel API Token Brute-Force (CVE-2026-73056)

CVE-2026-74791: Scriban before 7

SiYuan Stored XSS in Attribute-View Select Options (CVE-2026-73050)

SiYuan Kernel API Token Brute-Force (CVE-2026-73056)

CVE-2026-73050 - Exploits & Severity - Feedly

CVE-2026-74791: Scriban before 7

SiYuan Stored XSS in Attribute-View Select Options (CVE-2026-73050)

CVE-2026-73050: SiYuan before v3.7.4 Stored XSS via select option color [CRITICAL] CVSS 9.4

Collect, analyze, and vulnerability reports faster using AI