CVE-2026-73041
published 2026-08-15CVE-2026-73041: SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious…
PriorityP350critical9CVSS 3.1
AVNACLPRLUIRSCCHIHAH
EPSS
0.23%
14.6th percentile
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js access when a user opens an annotated PDF.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siyuan-note | siyuan | < 3.7.4 | 3.7.4 |
CVSS provenance
nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
nvdv4.09.4CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint.
ghsa_unreviewed·2026-08-16
CVE-2026-73041 [CRITICAL] CWE-79 SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint.
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js access when a user opens an annotated PDF.
VulDB
siyuan-note SiYuan up to 3.7.3 SetFileAnnotation Endpoint cross site scripting
vuldb·2026-08-16·CVSS 9.0
CVE-2026-73041 [CRITICAL] siyuan-note SiYuan up to 3.7.3 SetFileAnnotation Endpoint cross site scripting
A vulnerability, which was classified as problematic, was found in siyuan-note SiYuan up to 3.7.3. This vulnerability affects unknown code of the component SetFileAnnotation Endpoint. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2026-73041. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-15
Published