Stored Cross-Site Scripting in SiYuan by SiYuan Note
CVE-2026-73050
9.4CRITICAL
What is CVE-2026-73050?
Versions of SiYuan prior to v3.7.4 are vulnerable to stored cross-site scripting due to inadequate validation and escaping of the color field in attribute-view select options. Attackers can exploit this flaw by injecting malicious event-handler attributes through the color value, enabling arbitrary JavaScript execution within affected databases. This vulnerability is present at multiple unescaped render sites, posing a significant risk to users and their data.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
