Skip to content
CVE-2026-73053 - Exploits & Severity

CVE-2026-73053 - Exploits & Severity

Feedly • August 16, 2026

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79)

SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with Node integration enabled, achieving arbitrary code execution on the host system.

An authenticated attacker with low privileges over the network can craft malicious document icons with hex-encoded markup that execute arbitrary code on the host system with the privileges of the SiYuan renderer process when the user interacts with the crafted icon.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

A patch is available in SiYuan version v3.7.4 and later.

Upgrade SiYuan to version v3.7.4 or later. Until patching is possible, restrict access to document icon creation and modification to trusted users only, and consider disabling Node integration in the renderer if application functionality permits.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

NVD published the first details for CVE-2026-73053

Feedly found the first article mentioning CVE-2026-73053 . See article

A CVSS base score of 9 has been assigned.

GitHub Advisories released a security advisory .

CVE-2026-73053 - Exploits & Severity - Feedly

CVE-2026-73053: CRITICAL XSS in SiYuan (pre-v3.7.4) risks code execution on host via crafted icons when Node integration is enabled. No patch confirmed — disable Node integration or avoid untrusted files. #OffSeq #XSS #Vuln #SiYuan

CVE-2026-73053: SiYuan before v3.7.4 Cross-Site Scripting via unicode2Emoji [CRITICAL] CVSS 9.4

CVE-2026-73053 - SiYuan before v3.7.4 Cross-Site Scripting via unicode2Emoji

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities