What is CVE-2026-73052?
A critical vulnerability in SiYuan note-taking application before v3.7.4 where attribute-view field names are stored without HTML escaping and interpolated into sort menu option elements via innerHTML. This allows attackers to inject malicious markup through renamed database fields, leading to arbitrary JavaScript execution when users open the sort menu.
Azərbaycanca: SiYuan qeyd tətbiqində aşkar edilmiş kritik zəiflikdir. v3.7.4-dən əvvəlki versiyalarda, atribut-görünüş sahə adları sort menyusunda innerHTML vasitəsilə HTML qaçışı olmadan göstərilir. İstifadəçilər sort menyusunu açdıqda, zərərverici tərəfindən dəyişdirilmiş verilənlər bazası sahə adı ixtiyari JavaScript kodunun işə düşməsinə səbəb ola bilər.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of SiYuan note-taking application are affected by CVE-2026-73052?
Versions before v3.7.4 are affected by this vulnerability.
How is CVE-2026-73052 exploited?
Attackers can inject malicious markup through renamed database fields. These field names are stored without HTML escaping and interpolated into sort menu option elements via innerHTML. When users open the sort menu, arbitrary JavaScript code can be executed.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.