CRITICAL 9.4 NVD
CVE-2026-73043
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and s
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and JavaScript into template calculations that execute in the desktop client renderer with Node integration enabled, allowing arbitrary code execution when the database is opened.
References
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-rwh7-gm74-67h6
- https://www.vulncheck.com/advisories/siyuan-before-remote-code-execution-via-template-calc
This critical severity vulnerability with a CVSS score of 9.4 was published on 2026-08-15 via NVD.
Risk Timeline
CVE Disclosed2026-08-15 · 0 days ago
Remediation Resources
vulnfeed aggregates 11804 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.