CVE-2026-74801

8.2

SiYuan · SiYuan

SiYuan is vulnerable to OS command injection, which can lead to local privilege escalation when leveraging the elevator executable.

Executive summary

A critical OS command injection vulnerability in SiYuan allows an authenticated local attacker to escalate privileges and gain full control over the affected system.

Vulnerability

The application is susceptible to OS command injection (CWE-78). An attacker with low privileges can exploit this flaw to execute arbitrary system commands, potentially leading to total system compromise.

Business impact

The ability to escalate privileges from a low-level user to full system control represents a critical security failure. With a CVSS score of 8.2, this vulnerability could be used by an attacker to exfiltrate sensitive data, install persistent backdoors, or disrupt core business operations.

Remediation

Immediate Action: Update the SiYuan application to version 3.7.4 or later immediately.

Proactive Monitoring: Monitor for unexpected execution of system utilities or unusual child processes spawned by the SiYuan application.

Compensating Controls: Limit user permissions on the host operating system to prevent unauthorized access to sensitive application directories and executables.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the existence of a proof of concept and the potential for total system compromise, this issue must be addressed with the highest priority. All instances of SiYuan should be updated to the latest version to neutralize the command injection vector.

More SiYuan CVEs