CVE-2026-73042
published 2026-08-15CVE-2026-73042: SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group…
PriorityP351critical9CVSS 3.1
AVNACLPRLUIRSCCHIHAH
EPSS
0.30%
22.9th percentile
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names that close containing elements and execute arbitrary code via event handlers, reaching Node built-ins due to Electron's insecure configuration.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siyuan-note | siyuan | < 3.7.4 | 3.7.4 |
CVSS provenance
nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
nvdv4.09.4CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
SiYuan-Note SiYuan up to 3.7.3 HTML Interpolation HTML injection
vuldb·2026-08-16·CVSS 9.0
CVE-2026-73042 [CRITICAL] SiYuan-Note SiYuan up to 3.7.3 HTML Interpolation HTML injection
A vulnerability has been found in SiYuan-Note SiYuan up to 3.7.3 and classified as problematic. This issue affects some unknown processing of the component HTML Interpolation. Performing a manipulation results in HTML injection.
This vulnerability is known as CVE-2026-73042. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
GHSA
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus.
ghsa_unreviewed·2026-08-16
CVE-2026-73042 [CRITICAL] CWE-79 SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus.
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names that close containing elements and execute arbitrary code via event handlers, reaching Node built-ins due to Electron's insecure configuration.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-15
Published