What is CVE-2026-74801?
CVE-2026-74801: In SiYuan versions prior to 3.7.4, improper escaping of workspace directory paths when constructing command-line arguments for the elevated 'elevator.exe' helper process allows remote code execution. An attacker can create a malicious workspace directory with command metacharacters in its path and trigger the Microsoft Defender exclusion flow. Users should immediately update SiYuan to version 3.7.4 or later.
Azərbaycanca: CVE-2026-74801: SiYuan qeyd tətbiqinin 3.7.4-dən əvvəlki versiyalarında `elevator.exe` köməkçi prosesi üçün komanda arqumentləri qurularkən workspace qovluq yollarının düzgün escap edilməməsi səbəbindən məsafədən kod icrası boşluğu mövcuddur. Təcavüzkar, yolunda xüsusi simvollar olan zərərli iş sahəsi qovluğu yaradaraq Microsoft Defender istisna axınını tetikleye bilər. İstifadəçilər dərhal SiYuan-ı 3.7.4 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which versions of SiYuan are affected by CVE-2026-74801?
This remote code execution (RCE) vulnerability affects SiYuan versions prior to 3.7.4.
How can an attacker exploit CVE-2026-74801?
An attacker can create a malicious workspace directory with command metacharacters in its path and trigger the Microsoft Defender exclusion flow, because workspace directory paths are improperly escaped when constructing command-line arguments for the 'elevator.exe' helper process.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.