CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-73042 — SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML int...

·Source: NIST NVD

Updated:

Executive Summary

SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names that close containing elements and execute arbitrary code via event handlers, reaching Node built-ins due to Electron's insecure configuration.

Analysis

SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names that close containing elements and execute arbitrary code via event handlers, reaching Node built-ins due to Electron's insecure configuration. CVSS Score: 9. Published: 2026-08-15T22:16:54.030.

Indicators of Compromise (1)

CVE (1)
CVE-2026-73042
Source Attribution

Originally published by NIST NVD on Aug 15, 2026. Verified by: NIST.

Related Threats