What is CVE-2026-73041?
CVE-2026-73041: SiYuan versions before v3.7.4 fail to validate or escape annotation fields, allowing attackers to inject malicious markup via the setFileAnnotation endpoint. This markup executes as script in the PDF renderer with full Node.js access when a user opens an annotated PDF. Users should upgrade to v3.7.4 or later immediately.
Azərbaycanca: CVE-2026-73041: SiYuan proqramının v3.7.4-dən əvvəlki versiyalarında annotation sahələrinin yoxlanılmaması və ya escape edilməməsi zəifliyi mövcuddur. Təcavüzkar setFileAnnotation endpointi vasitəsilə zərərli markup inject edə bilər ki, bu da PDF açıldıqda renderer daxilində Node.js imtiyazları ilə skript icrasına səbəb olur. SiYuan istifadəçiləri dərhal v3.7.4 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: SiYuan
FAQ2
Which versions of SiYuan are affected by CVE-2026-73041?
The vulnerability affects all versions of SiYuan prior to v3.7.4.
How can I protect against CVE-2026-73041?
SiYuan users should immediately upgrade to v3.7.4 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.