What is CVE-2026-74902?
CVE-2026-74902: SiYuan versions before v3.7.4 contain a Cross-Site Scripting (XSS) vulnerability in the file upload validation flow, where filenames are not escaped before being inserted into HTML via `insertAdjacentHTML`. Attackers can execute scripts with full OS command access by crafting malicious filenames. Upgrade to v3.7.4 or later immediately.
Azərbaycanca: CVE-2026-74902: SiYuan proqramının v3.7.4-dən əvvəlki versiyalarında fayl yükləmə doğrulama prosesində Cross-Site Scripting (XSS) zəifliyi aşkarlanıb. Təcavüzkar, fayl adına skript yerləşdirərək `insertAdjacentHTML` vasitəsilə tam OS əmri icra etmək imkanı əldə edə bilər. Dərhal v3.7.4 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: SiYuan
FAQ2
Which software is affected by CVE-2026-74902?
CVE-2026-74902 affects SiYuan versions before v3.7.4.
How can users protect against CVE-2026-74902?
It is recommended to immediately upgrade SiYuan to v3.7.4 or a later version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.