Critical Stored XSS Vulnerability in SiYuan Affects Users

Critical Stored XSS Vulnerability in SiYuan Affects Users

First seen 16 Aug 2026, 10:03 UTC Feedlyexploit-intel.comwww.thehackerwire.cominfosec.exchange 91% similarity 78.0

Article Content

Browse articles
ThreatCluster

A critical stored cross-site scripting (XSS) vulnerability, CVE-2026-73052, has been identified in SiYuan versions prior to 3.7.4. This flaw allows attackers to inject arbitrary JavaScript by renaming database fields, which can lead to remote code execution on desktop clients with Node integration enabled. The vulnerability requires user interaction to exploit, as it activates when users open the sort menu. Currently, there is no public proof-of-concept or evidence of exploitation. Users are advised to upgrade to version 3.7.4 or later and restrict permissions for renaming database fields. The CVSS base score for this vulnerability is 9.4, indicating a critical severity level. Security advisories have been issued, emphasizing the urgency of patching affected systems.

Key Points: • CVE-2026-73052 is a critical stored XSS vulnerability in SiYuan before v3.7.4. • Attackers can exploit this flaw to execute arbitrary JavaScript on affected systems. • Users are urged to upgrade to version 3.7.4 to mitigate the risk of exploitation.

ThreatCluster AI How this analysis works

Timeline

2026-08-15
CVE-2026-73052 published
The vulnerability was officially disclosed, detailing the risk of stored XSS in SiYuan versions before 3.7.4.
Feedly
2026-08-15
CVE-2026-73043 published
Another critical vulnerability in SiYuan was disclosed, indicating multiple security issues.
Feedly
Recent
Security advisories released
Advisories were issued urging users to upgrade and restrict permissions to mitigate risks.
exploit-intel.com

Community

Browse all →