Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79)
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with Node integration enabled, achieving arbitrary code execution on the host system.
An authenticated attacker with low privileges over the network can craft malicious document icons with hex-encoded markup that execute arbitrary code on the host system with the privileges of the SiYuan renderer process when the user interacts with the crafted icon.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
A patch is available in SiYuan version v3.7.4 and later.
Upgrade SiYuan to version v3.7.4 or later. Until patching is possible, restrict access to document icon creation and modification to trusted users only, and consider disabling Node integration in the renderer if application functionality permits.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
NVD published the first details for CVE-2026-73053
Feedly found the first article mentioning CVE-2026-73053 . See article
A CVSS base score of 9 has been assigned.
GitHub Advisories released a security advisory .
CVE-2026-73053 - Exploits & Severity - Feedly
CVE-2026-73053: CRITICAL XSS in SiYuan (pre-v3.7.4) risks code execution on host via crafted icons when Node integration is enabled. No patch confirmed — disable Node integration or avoid untrusted files. #OffSeq #XSS #Vuln #SiYuan
CVE-2026-73053: SiYuan before v3.7.4 Cross-Site Scripting via unicode2Emoji [CRITICAL] CVSS 9.4
CVE-2026-73053 - SiYuan before v3.7.4 Cross-Site Scripting via unicode2Emoji
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
