What is CVE-2026-73047?
CVE-2026-73047 is a server-side template injection vulnerability in Siyuan versions <= 3.7.3, within the attribute-view Template calculation feature. It stems from the Sprig template engine exposing dangerous functions like `env` and `expandenv` without restriction. Users must upgrade to version 3.7.4 immediately.
Azərbaycanca: CVE-2026-73047, Siyuan qeyd proqramının 3.7.3 və daha əvvəlki versiyalarında "attribute-view Template calculation" xüsusiyyətində server-side template injection zəifliyidir. Bu zəiflik Sprig şablon mühərrikinin `env`, `expandenv` kimi təhlükəli funksiyalarını məhdudlaşdırmaması səbəbindən yaranır. İstifadəçilər dərhal 3.7.4 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which versions of Siyuan are affected by CVE-2026-73047?
This vulnerability affects Siyuan versions 3.7.3 and earlier.
What is the root cause of CVE-2026-73047?
The vulnerability stems from the Sprig template engine not restricting dangerous functions like `env` and `expandenv`.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.