Stored Cross-Site Scripting in SiYuan by SiYuan Technologies
CVE-2026-73044
9.4CRITICAL
What is CVE-2026-73044?
SiYuan versions before v3.7.4 are susceptible to a stored cross-site scripting vulnerability due to inadequate validation and escaping of table column width values. This flaw permits attackers to inject harmful payloads via the setAttrViewColWidth API, which can break out of style attributes. As a result, event handlers can be injected into table cells, enabling the execution of arbitrary code within the Electron renderer, especially when Node integration is enabled. This vulnerability poses significant security risks by allowing potential exploitation through malicious scripts.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
