SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort menu, with Node integration enabled in the desktop client enabling code execution.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-15 22:16
Updated : 2026-08-26 17:05
NVD link : CVE-2026-73052
Mitre link : CVE-2026-73052
CVE.ORG link : CVE-2026-73052
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
