What is CVE-2026-74800?
CVE-2026-74800 is a vulnerability in SiYuan note-taking software before v3.7.4, where missing Content-Disposition and X-Content-Type-Options headers when serving asset files allows stored XSS attacks. Authenticated attackers can execute scripts via uploaded HTML files to gain full kernel API access in the workspace owner's context. Users should upgrade to v3.7.4 or later.
Azərbaycanca: CVE-2026-74800 SiYuan not yükləmə platformasının 3.7.4 versiyasından əvvəlki versiyalarında asset faylları təqdim edərkən Content-Disposition və X-Content-Type-Options başlıqlarını təyin etməməsi ilə bağlı zəiflikdir. Bu, autentifikasiya olunmuş hücumçulara yüklənmiş HTML faylları vasitəsilə stored XSS hücumu edərək, workspace sahibinin kernel API girişini əldə etməyə imkan verir. İstifadəçilərə dərhal v3.7.4 və ya daha yuxarı versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: SiYuan
FAQ2
What risk does CVE-2026-74800 pose in SiYuan?
It allows authenticated attackers to perform stored XSS attacks via uploaded HTML files, gaining full kernel API access in the workspace owner's context.
How can users protect against CVE-2026-74800?
Users should immediately upgrade SiYuan to version 3.7.4 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.