cvefeed.io Critical Stored XSS Vulnerabilities Found in SiYuan Versions Before 3.7.4
Article Content
- •CVE-2026-73050 and CVE-2026-73052 are critical XSS vulnerabilities in SiYuan before v3.7.4.
- •Both vulnerabilities allow for arbitrary JavaScript execution, with potential for severe impacts.
- •Users must upgrade to SiYuan v3.7.4 or later to mitigate these risks.
Two critical vulnerabilities, CVE-2026-73050 and CVE-2026-73052, have been identified in SiYuan versions prior to 3.7.4. CVE-2026-73050 allows attackers to exploit stored cross-site scripting (XSS) via unescaped color fields in select options, executing arbitrary JavaScript in victim browsers. CVE-2026-73052 enables similar attacks through unescaped attribute-view field names, potentially leading to arbitrary code execution on systems with Node integration enabled. Both vulnerabilities require authenticated access for exploitation, and no public proof-of-concept exploits are currently available. Users are advised to upgrade to version 3.7.4 or later to mitigate these risks. The vulnerabilities have been assigned a CVSS score of 9.4, indicating their critical nature. Security advisories have been released, urging immediate action to restrict access and review existing configurations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (17)
Following this threat?
Track CVE-2026-73043 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Twitch Chat Messages Exploit OBS Studio via Chromium Vulnerability A vulnerability in OBS Studio allows malicious Twitch chat messages to execute native code on streamers' Windows PCs. This exploit targets users running OBS Studio version 32.2.2 or older, leveraging a cross-site scripting (XSS) flaw in custom overlays that render viewer messages as unsanitized HTML. The attack…