CVE-2026-74800: SiYuan before v3.7.4 Stored XSS via assets endpoint
SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can upload HTML files as assets and execute scripts with full kernel API access when the workspace owner opens the asset link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-74800?
CVE-2026-74800 is classified as critical with a severity score of 9.
How do I fix CVE-2026-74800?
To mitigate CVE-2026-74800, upgrade SiYuan to version 3.7.4 or later which addresses the stored XSS vulnerability.
What type of vulnerability is CVE-2026-74800?
CVE-2026-74800 is a stored cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2026-74800?
Authenticated users of SiYuan before version 3.7.4 can exploit CVE-2026-74800 if they can upload HTML files.
What impact does CVE-2026-74800 have?
CVE-2026-74800 can allow attackers to execute scripts with full kernel API access on the affected system.