← Volver al buscador de CVEs

CVE-2026-73041

SiYuan

Descripción

SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js access when a user opens an annotated PDF.

CVSS 9EPSS 0.234%Riesgo 0.92
Ver fuente
Publicación
2026-08-15 22:16:53
Versiones afectadas
<3.7.4
Tipo
Aplicación web
Última modificación
2026-08-26 17:05:08
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H