What is CVE-2026-73042?
SiYuan versions before v3.7.4 fail to properly escape database menu metadata during HTML interpolation. This allows attackers to inject malicious scripts through field descriptions or names, which execute when users open group, view, or field-edit menus. Affected systems must be immediately updated to v3.7.4 or later to mitigate the risk.
Azərbaycanca: SiYuan proqramının 3.7.4 versiyasından əvvəlki versiyalarında verilənlər bazası menyu metadata-sının HTML interpolasiyası zamanı düzgün escape edilməməsi aşkarlanıb. Bu boşluq təcavüzkara field təsvirləri və ya adları vasitəsilə zərərli skript yükləməyə imkan verir ki, bu da istifadəçi menyuları açdıqda işə düşür. Təsirə məruz qalan sistemlərdə dərhal v3.7.4 və ya daha yuxarı versiyaya yeniləmə aparılmalıdır.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What causes the CVE-2026-73042 vulnerability in SiYuan?
Improper escaping of field descriptions or names during HTML interpolation of database menu metadata allows malicious script injection.
How can users protect against the CVE-2026-73042 vulnerability?
Affected SiYuan systems must be immediately updated to v3.7.4 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.