What is CVE-2026-73043?
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores the output without sanitization. This allows attackers to inject malicious HTML and JavaScript into template calculations. Users should update to version v3.7.4 or later immediately.
Azərbaycanca: SiYuan qeyd sisteminin v3.7.4 versiyasından əvvəlki versiyalarında, Template hesablama operatorunda uzaqdan kod icrası (RCE) boşluğu aşkarlanıb. Bu boşluq istifadəçilərin hazırladığı Go şablonlarının təmizlənmədən saxlanması səbəbindən yaranır. İstifadəçilər dərhal ən son v3.7.4 versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: SiYuan
FAQ2
Which versions of SiYuan are affected by CVE-2026-73043?
This vulnerability affects all versions of SiYuan before v3.7.4.
What causes the RCE vulnerability in CVE-2026-73043?
The vulnerability is caused by the Template calculation operator storing user-authored Go templates without sanitization.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.