CVE-2026-73050
Received Received - Intake

SiYuan Stored XSS via Unescaped Color Field in Attribute-View

Vulnerability report for CVE-2026-73050, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-15

Last updated on: 2026-08-15

Assigner: VulnCheck

Description

SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotation marks in the color value, executing arbitrary JavaScript when viewing databases containing the malicious select field.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-15
Last Modified
2026-08-15
Generated
2026-08-16
AI Q&A
2026-08-16
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SiYuan versions before v3.7.4 have a stored cross-site scripting vulnerability due to improper validation or escaping of the color field in attribute-view select options. Attackers can inject malicious JavaScript by including quotation marks in the color value, which executes when others view databases containing the compromised select field.

Detection Guidance

This vulnerability involves stored cross-site scripting in SiYuan versions before v3.7.4 due to improper escaping of the color field in attribute-view select options. To detect it, inspect SiYuan databases for malicious JavaScript in select field color values, particularly those containing event-handler attributes or quotation marks.

Impact Analysis

This vulnerability allows attackers to execute arbitrary JavaScript in your browser when you view a database with a malicious select field. This could lead to unauthorized actions, data theft, or session hijacking if you interact with the compromised content.

Compliance Impact

This vulnerability allows stored cross-site scripting (XSS) via unescaped color fields in attribute-view select options. Such attacks could lead to unauthorized data access or manipulation, which may violate GDPR's integrity and confidentiality requirements or HIPAA's safeguards for protected health information.

Mitigation Strategies

Upgrade SiYuan to version v3.7.4 or later to address the vulnerability. If upgrading is not immediately possible, restrict database access to trusted users and avoid opening databases from untrusted sources until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73050. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart