Stored Cross-Site Scripting Vulnerability in SiYuan by SiYuan Note
CVE-2026-74800
9.4CRITICAL
What is CVE-2026-74800?
SiYuan versions prior to v3.7.4 are vulnerable to a stored cross-site scripting flaw due to improper handling of Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets. This allows authenticated attackers to upload malicious HTML files as assets. When the workspace owner accesses the link to these assets, the scripts can be executed with full kernel API access, posing a significant security risk.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
