What is CVE-2026-73050?
CVE-2026-73050 is a stored cross-site scripting (XSS) vulnerability in SiYuan versions before v3.7.4, caused by a failure to validate or escape the color field in attribute-view select options. Attackers can inject event-handler attributes by including quotation marks in the color value, leading to arbitrary JavaScript execution in users' browsers. Upgrading to SiYuan v3.7.4 or later is recommended to mitigate the issue.
Azərbaycanca: CVE-2026-73050, SiYuan platformasının v3.7.4-dən əvvəlki versiyalarında attribute-view seçimlərində rəng sahəsinin düzgün yoxlanılmaması səbəbindən stored cross-site scripting (XSS) zəifliyidir. Təcavüzkar rəng dəyərinə dırnaq işarələri daxil edərək hadisə idarəedici atributlarını yeridə və istifadəçi brauzerində özbaşına JavaScript kodu icra edə bilər. Problemi aradan qaldırmaq üçün SiYuan-ı v3.7.4 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of SiYuan are affected by CVE-2026-73050?
CVE-2026-73050 affects SiYuan versions before v3.7.4.
How can I protect against the stored XSS vulnerability in CVE-2026-73050?
Upgrading to SiYuan v3.7.4 or later is recommended to mitigate the vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.