CVE-2026-73052: SiYuan before v3.7.4 Stored XSS via Attribute-View Field Names
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort menu, with Node integration enabled in the desktop client enabling code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuan desktop clientto a version that resolves this vulnerability.Fixed in 3.7.4 - Compensating control
Disable Node integration in the SiYuan desktop client (where applicable) to prevent JavaScript code execution when an injected payload is rendered.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73052?
CVE-2026-73052 has a critical severity rating of 9.
How do I fix CVE-2026-73052?
To fix CVE-2026-73052, upgrade to SiYuan version 3.7.4 or later.
What kind of vulnerability is CVE-2026-73052?
CVE-2026-73052 is a Stored Cross-Site Scripting (XSS) vulnerability.
What can attackers do with CVE-2026-73052?
Attackers can inject arbitrary JavaScript into the sort menu by renaming a database field.
What versions of SiYuan are affected by CVE-2026-73052?
All versions of SiYuan prior to 3.7.4 are affected by CVE-2026-73052.