CVE-2026-73042: SiYuan before v3.7.4 Remote Code Execution via Menu Metadata
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names that close containing elements and execute arbitrary code via event handlers, reaching Node built-ins due to Electron's insecure configuration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in 3.7.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73042?
CVE-2026-73042 has a severity rating of critical, with a score of 9.
How do I fix CVE-2026-73042?
To fix CVE-2026-73042, upgrade SiYuan to version 3.7.4 or later.
What type of attack can CVE-2026-73042 enable?
CVE-2026-73042 can enable remote code execution via script injection through improperly escaped HTML.
Which software versions are affected by CVE-2026-73042?
CVE-2026-73042 affects all versions of SiYuan before v3.7.4.
What is the impact of exploiting CVE-2026-73042?
Exploiting CVE-2026-73042 allows attackers to execute arbitrary scripts when users interact with specific menus.