What is CVE-2026-73053?
CVE-2026-73053 is an XSS vulnerability in SiYuan before v3.7.4, located in the unicode2Emoji function which fails to sanitize codepoint output. It allows attackers to achieve arbitrary code execution via crafted document icons with Node integration enabled. Users should upgrade to v3.7.4 or later immediately.
Azərbaycanca: CVE-2026-73053 SiYuan proqramında aşkarlanan XSS zəifliyidir (unicode2Emoji funksiyasında). Bu, v3.7.4-dən əvvəlki versiyalara təsir edir və təcavüzkarlara sənəd ikonları vasitəsilə ixtiyari kod icra etməyə imkan verə bilər. İstifadəçilər dərhal v3.7.4 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: SiYuan
FAQ2
In which function of SiYuan was CVE-2026-73053 discovered?
The vulnerability was discovered in the unicode2Emoji function.
What measure should be taken to protect against CVE-2026-73053?
Users should upgrade to v3.7.4 or later immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.