What is CVE-2026-75916?
CVE-2026-75916 is a cross-site scripting (XSS) vulnerability in SiYuan note-taking application up to version 3.7.3, affecting the '((' block-reference autocomplete hint popup. The vulnerability exists in the `genHintItemHTML()` function where block name, alias, and memo fields are inserted into HTML without proper escaping, potentially allowing remote code execution. Users should update to the latest version to mitigate this issue.
Azərbaycanca: CVE-2026-75916 SiYuan qeydiyyat tətbiqinin 3.7.3 versiyasına qədər olan versiyalarında '((' blok-istinad avtomatik tamamlama pəncərəsində aşkarlanan cross-site scripting (XSS) zəifliyidir. Bu zəiflik `genHintItemHTML()` funksiyasında istifadəçi tərəfindən daxil edilmiş məlumatların (ad, alias, memo) filtrasiya edilməməsi səbəbindən baş verir və uzaqdan kod icrasına imkan yarada bilər. İstifadəçilərə proqramı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the SiYuan application are affected by the CVE-2026-75916 XSS vulnerability?
The CVE-2026-75916 vulnerability affects SiYuan note-taking application up to version 3.7.3.
What should users do to protect themselves from CVE-2026-75916?
Users should update the SiYuan application to the latest version to mitigate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.