CVE-2026-73041: SiYuan before v3.7.4 Remote Code Execution via PDF Annotations
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js access when a user opens an annotated PDF.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in 3.7.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73041?
The severity of CVE-2026-73041 is critical with a score of 9.
What risk does CVE-2026-73041 pose?
CVE-2026-73041 poses a risk of remote code execution through malicious PDF annotations.
How do I fix CVE-2026-73041?
To fix CVE-2026-73041, upgrade SiYuan to version 3.7.4 or later.
Which software is affected by CVE-2026-73041?
SiYuan versions before v3.7.4 are affected by CVE-2026-73041.
What attack vector is exploited in CVE-2026-73041?
CVE-2026-73041 exploits the setFileAnnotation endpoint where malicious markup can be injected.