Junglewise Threat Intelligence

CVE-2026-73044: SiYuan stored cross-site scripting in table column width

CVE-2026-73044 · Severity: critical · CVSS 9 · Published 2026-08-15

Technologies: SiYuan. Vendors: SiYuan.

Executive brief

SiYuan is a note-taking application that stores data locally and can synchronize across devices. Versions before 3.7.4 fail to validate table column width values, allowing attackers to inject malicious code that executes in the desktop application. An attacker can exploit this by creating a shared or synchronized database with a crafted column width, which then executes arbitrary code when the database is opened, potentially compromising the user's system.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in SiYuan's attribute-view table rendering. The setAttrViewColWidth API accepts an arbitrary string for table column widths without validation or escaping. The width value is then interpolated directly into HTML style attributes in four frontend rendering locations (render.ts and row.ts) without proper HTML encoding. An attacker can inject a quotation mark followed by event handler attributes (e.g., `200px" onmouseover="alert(1)`) to break out of the style attribute and inject executable code. The injected handler executes on every table cell in the affected column. Since the SiYuan Electron desktop application enables nodeIntegration and disables contextIsolation and webSecurity, the injected script gains access to Node.js APIs including child_process, allowing arbitrary code execution with user privileges. Patch version 3.7.4 addresses this issue.

Affected products

  • SiYuan SiYuan before 3.7.4

Timeline

  • 2026-08-15: disclosed
  • 2026-08-15: patched: v3.7.4

References

Related threats