CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-74800 — SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options...

·Source: NIST NVD

Updated:

Executive Summary

SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can upload HTML files as assets and execute scripts with full kernel API access when the workspace owner opens the asset link.

Analysis

SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can upload HTML files as assets and execute scripts with full kernel API access when the workspace owner opens the asset link. CVSS Score: 9. Published: 2026-08-17T11:16:40.187.

Indicators of Compromise (1)

CVE (1)
CVE-2026-74800
Source Attribution

Originally published by NIST NVD on Aug 17, 2026. Verified by: NIST.

Related Threats