What is CVE-2026-75917?
CVE-2026-75917 is a cross-site scripting (XSS) vulnerability found in SiYuan versions prior to v3.7.4, triggered through document metadata fields (e.g., bookmark, alias, memo) during hover-tooltip generation in the file-tree picker. Users are advised to upgrade SiYuan to version v3.7.4 or later to mitigate the issue.
Azərbaycanca: CVE-2026-75917, SiYuan proqramının v3.7.4 versiyasından əvvəlki versiyalarında aşkarlanan cross-site scripting (XSS) zəifliyidir. Bu zəiflik fayl ağacı seçimi dialoqlarında hover-tooltip generasiyası zamanı sənəd metadata sahələrindən (bookmark, alias, memo) qaynaqlanır. İstifadəçilərə SiYuan proqramını v3.7.4 və ya daha yeni versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: SiYuan
FAQ2
Which versions of SiYuan are affected by CVE-2026-75917?
This XSS vulnerability affects SiYuan versions prior to v3.7.4.
How can the CVE-2026-75917 vulnerability be mitigated?
It is recommended to upgrade SiYuan to version v3.7.4 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.