Skip to content
Critical Stored XSS Vulnerabilities Found in SiYuan Versions Before 3.7.4

Critical Stored XSS Vulnerabilities Found in SiYuan Versions Before 3.7.4

First seen 16 Aug 2026, 10:03 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 17, 2026 at 09:19 UTC
  • •CVE-2026-73050 and CVE-2026-73052 are critical XSS vulnerabilities in SiYuan before v3.7.4.
  • •Both vulnerabilities allow for arbitrary JavaScript execution, with potential for severe impacts.
  • •Users must upgrade to SiYuan v3.7.4 or later to mitigate these risks.

Two critical vulnerabilities, CVE-2026-73050 and CVE-2026-73052, have been identified in SiYuan versions prior to 3.7.4. CVE-2026-73050 allows attackers to exploit stored cross-site scripting (XSS) via unescaped color fields in select options, executing arbitrary JavaScript in victim browsers. CVE-2026-73052 enables similar attacks through unescaped attribute-view field names, potentially leading to arbitrary code execution on systems with Node integration enabled. Both vulnerabilities require authenticated access for exploitation, and no public proof-of-concept exploits are currently available. Users are advised to upgrade to version 3.7.4 or later to mitigate these risks. The vulnerabilities have been assigned a CVSS score of 9.4, indicating their critical nature. Security advisories have been released, urging immediate action to restrict access and review existing configurations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 45d ago How this analysis works

Timeline

2026-08-15
CVE-2026-73050 published
Details released about a critical stored XSS vulnerability in SiYuan affecting versions before 3.7.4.
Feedly
2026-08-15
CVE-2026-73052 published
Critical HTML injection vulnerability disclosed for SiYuan versions prior to 3.7.4, allowing code execution.
Feedly
2026-08-15
CVE-2026-73043 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-16
Security advisories released
GitHub Advisories and other platforms issued warnings about the critical vulnerabilities in SiYuan.
Feedly

More articles in this cluster (17)

Following this threat?

Track CVE-2026-73043 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed