CVE-2026-73043

9.0

siyuan-note · siyuan

SiYuan versions before 3.7.4 contain a remote code execution vulnerability in the Template calculation operator, allowing execution of arbitrary code via injected malicious templates.

Executive summary

A critical remote code execution vulnerability in the SiYuan desktop client allows an attacker to execute arbitrary code when a malicious database is opened.

Vulnerability

This is a cross-site scripting (CWE-79) and remote code execution vulnerability originating from the Template calculation operator. The operator fails to sanitize user-authored Go templates, which are rendered with Node integration enabled in the desktop client.

Business impact

Successful exploitation allows an attacker to achieve code execution on the host machine running the SiYuan desktop client. This could lead to local data theft, lateral movement within the network, or complete control over the user's workstation, justifying the critical severity rating.

Remediation

Immediate Action: Upgrade the SiYuan desktop client to version 3.7.4 or later immediately.

Proactive Monitoring: Users should exercise caution when opening database files from untrusted sources and monitor for unexpected application behavior or unauthorized network connections.

Compensating Controls: Ensure the application is run with the least privilege necessary and utilize endpoint protection software to detect unauthorized child processes spawned by the SiYuan client.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

All users of the SiYuan desktop client must update to version 3.7.4 to remediate this vulnerability. Given the ease with which local code execution can occur, users should avoid opening untrusted or shared SiYuan database files until the software has been patched.

More siyuan-note CVEs