What is CVE-2026-73044?
A stored cross-site scripting vulnerability exists in SiYuan note-taking software versions before v3.7.4 due to improper validation and escaping of table column width values. Attackers can inject malicious payloads via the setAttrViewColWidth API, escaping style attributes to insert event handlers. It is recommended to upgrade SiYuan to version v3.7.4 or later.
Azərbaycanca: SiYuan qeyd tətbiqinin v3.7.4-dən əvvəlki versiyalarında cədvəl sütun genişliyi dəyərlərinin düzgün yoxlanılmaması səbəbindən stored XSS zəifliyi mövcuddur. Təcavüzkar setAttrViewColWidth API-si vasitəsilə style atributlarına zərərli kod yeridə bilər. Təsirə məruz qalan sistemlərdə SiYuan-ı ən azı v3.7.4 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of SiYuan are affected by CVE-2026-73044?
This stored XSS vulnerability affects SiYuan versions before v3.7.4.
How can the CVE-2026-73044 vulnerability be exploited?
An attacker can inject malicious payloads via the setAttrViewColWidth API by escaping style attributes in table column width values to insert event handlers.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.