CVE-2026-73043
published 2026-08-15CVE-2026-73043: SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and…
PriorityP356critical9CVSS 3.1
AVNACLPRLUIRSCCHIHAH
EPSS
0.37%
31.1th percentile
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and JavaScript into template calculations that execute in the desktop client renderer with Node integration enabled, allowing arbitrary code execution when the database is opened.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siyuan-note | siyuan | < 3.7.4 | 3.7.4 |
CVSS provenance
nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
nvdv4.09.4CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
siyuan-note SiYuan up to 3.7.3 Template calculation operator injection
vuldb·2026-08-16·CVSS 9.0
CVE-2026-73043 [CRITICAL] siyuan-note SiYuan up to 3.7.3 Template calculation operator injection
A vulnerability described as problematic has been identified in siyuan-note SiYuan up to 3.7.3. Affected is an unknown function of the component Template calculation operator. Executing a manipulation can lead to injection.
This vulnerability is registered as CVE-2026-73043. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
GHSA
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitizati
ghsa_unreviewed·2026-08-16
CVE-2026-73043 [CRITICAL] CWE-79 SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitizati
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and JavaScript into template calculations that execute in the desktop client renderer with Node integration enabled, allowing arbitrary code execution when the database is opened.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-15
Published