Critical Stored XSS Vulnerabilities Found in SiYuan Versions Before 3.7.4

Critical Stored XSS Vulnerabilities Found in SiYuan Versions Before 3.7.4

First seen 16 Aug 2026, 10:03 UTC Feedlywww.incibe.escvefeed.ioexploit-intel.cominfosec.exchange+1 78.0

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities, CVE-2026-73050 and CVE-2026-73052, have been identified in SiYuan versions prior to 3.7.4. CVE-2026-73050 allows attackers to exploit stored cross-site scripting (XSS) via unescaped color fields in select options, executing arbitrary JavaScript in victim browsers. CVE-2026-73052 enables similar attacks through unescaped attribute-view field names, potentially leading to arbitrary code execution on systems with Node integration enabled. Both vulnerabilities require authenticated access for exploitation, and no public proof-of-concept exploits are currently available. Users are advised to upgrade to version 3.7.4 or later to mitigate these risks. The vulnerabilities have been assigned a CVSS score of 9.4, indicating their critical nature. Security advisories have been released, urging immediate action to restrict access and review existing configurations.

Key Points: • CVE-2026-73050 and CVE-2026-73052 are critical XSS vulnerabilities in SiYuan before v3.7.4. • Both vulnerabilities allow for arbitrary JavaScript execution, with potential for severe impacts. • Users must upgrade to SiYuan v3.7.4 or later to mitigate these risks.

Ask AI about this cluster

Timeline

2026-08-15
CVE-2026-73050 published
Details released about a critical stored XSS vulnerability in SiYuan affecting versions before 3.7.4.
Feedly
2026-08-15
CVE-2026-73052 published
Critical HTML injection vulnerability disclosed for SiYuan versions prior to 3.7.4, allowing code execution.
Feedly
2026-08-15
CVE-2026-73043 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-16
Security advisories released
GitHub Advisories and other platforms issued warnings about the critical vulnerabilities in SiYuan.
Feedly