SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-73043

CRITICAL · CVSS 9 EPSS 0.37% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Versions of SiYuan prior to 3.7.4 are vulnerable to a critical remote code execution flaw in the Template calculation operator, which fails to sanitize user-generated Go templates. This allows attackers to inject malicious HTML and JavaScript, leading to arbitrary code execution when the affected database is accessed in a desktop client with Node integration enabled. Organizations using SiYuan should prioritize patching to mitigate this severe risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution arbitrary code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73043
Severity
CRITICAL
CVSS
9
EPSS
0.37%
Java

Original NVD Description

SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and JavaScript into template calculations that execute in the desktop client renderer with Node integration enabled, allowing arbitrary code execution when the database is opened.