Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79)
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort . Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort , with Node integration enabled in the desktop client enabling code execution.
An authenticated user with the ability to rename database fields can inject arbitrary JavaScript that executes when other users open the sort , and on the desktop client with Node integration enabled, this enables arbitrary code execution on the victim's system.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Upgrade SiYuan to version v3.7.4 or later. Additionally, restrict permissions for renaming database fields to trusted users only, and consider disabling Node integration in the desktop client if not required for functionality.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
NVD published the first details for CVE-2026-73052
Feedly found the first article mentioning CVE-2026-73052 . See article
A CVSS base score of 9 has been assigned.
A critical HTML injection vulnerability in SiYuan prior to version 3.7.4, with a CVSS score of 9, allows attackers to execute arbitrary JavaScript through the sort , escalating to arbitrary code execution on desktop clients due to Node integration. Exploitation requires user interaction after an attacker renames a database field to include malicious markup, but no public proof-of-concept exploits are available at this time. Users are advised to update to version 3.7.4 or newer to mitigate the risk. See article
GitHub Advisories released a security advisory .
SiYuan Critical RCE: Stored XSS in Metadata
SiYuan Desktop Client HTML Injection to RCE (CVE-2026-73052)
CVE-2026-73052 - Exploits & Severity - Feedly
CVE-2026-73052: SiYuan before v3.7.4 Stored XSS via Attribute-View Field Names [CRITICAL] CVSS 9.4
SiYuan RCE via Unsanitized Go Templates (CVE-2026-73043)
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
