CVE-2026-73052

SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort menu, with Node integration enabled in the desktop client enabling code execution.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-15 22:16

Updated : 2026-08-26 17:05


NVD link : CVE-2026-73052

Mitre link : CVE-2026-73052

CVE.ORG link : CVE-2026-73052


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')