CVE-2026-74800

SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can upload HTML files as assets and execute scripts with full kernel API access when the workspace owner opens the asset link.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-17 11:16

Updated : 2026-08-26 17:04


NVD link : CVE-2026-74800

Mitre link : CVE-2026-74800

CVE.ORG link : CVE-2026-74800


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')