CVE-2026-73043: SiYuan before v3.7.4 Remote Code Execution via Template Calculation
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and JavaScript into template calculations that execute in the desktop client renderer with Node integration enabled, allowing arbitrary code execution when the database is opened.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in 3.7.4 - Compensating control
Until upgrading, treat the database content/templates used by SiYuan as untrusted: prevent untrusted users from being able to open databases that may contain user-authored templates that execute in the desktop client renderer with Node integration enabled.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73043?
The severity of CVE-2026-73043 is critical with a score of 9.
What type of vulnerability is CVE-2026-73043?
CVE-2026-73043 is a remote code execution vulnerability.
How do I fix CVE-2026-73043?
To fix CVE-2026-73043, upgrade SiYuan to version 3.7.4 or later.
What impact does CVE-2026-73043 have?
CVE-2026-73043 allows attackers to execute arbitrary HTML and JavaScript code.
Which versions of SiYuan are affected by CVE-2026-73043?
SiYuan versions before v3.7.4 are affected by CVE-2026-73043.