CVE-2026-73050: SiYuan before v3.7.4 Stored XSS via select option color
SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotation marks in the color value, executing arbitrary JavaScript when viewing databases containing the malicious select field.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in v3.7.4 - Compensating control
Because the issue is stored XSS in SiYuan’s attribute-view select options, restrict access to user-accessible SiYuan database viewing pages (e.g., via network/ACL/WAF) until systems are upgraded to v3.7.4.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73050?
CVE-2026-73050 has a critical severity rating of 9.
How do I fix CVE-2026-73050?
To fix CVE-2026-73050, upgrade to SiYuan version 3.7.4 or later.
What type of vulnerability is CVE-2026-73050?
CVE-2026-73050 is a stored cross-site scripting (XSS) vulnerability.
What software is affected by CVE-2026-73050?
SiYuan versions before 3.7.4 are affected by CVE-2026-73050.
How does CVE-2026-73050 affect users?
CVE-2026-73050 allows attackers to execute arbitrary JavaScript on affected users' browsers.