LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-73041

Published
CVSS9
Severitycritical
WeaknessCWE-79
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Description

SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js access when a user opens an annotated PDF.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-73041

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-73041.