CVE-2026-75917

8.6

siyuan-note · siyuan

SiYuan is susceptible to a Cross-site Scripting vulnerability that can lead to remote code execution.

Executive summary

A critical cross-site scripting vulnerability in SiYuan software allows for remote code execution, posing a significant risk to local system integrity.

Vulnerability

This vulnerability is a Cross-site Scripting (CWE-79) flaw occurring during web page generation. An attacker can exploit this via a specially crafted request, requiring user interaction to execute arbitrary code with the privileges of the application.

Business impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the host machine. Given the CVSS score of 8.6, this represents a high-severity risk that could lead to total system compromise, unauthorized data access, and potential lateral movement within the network.

Remediation

Immediate Action: Update the SiYuan software to version 3.7.4 or later to apply the necessary security patches.

Proactive Monitoring: Review system and application logs for unusual request patterns, specifically those involving unexpected scripts or navigation to external resources.

Compensating Controls: Deploy a Web Application Firewall (WAF) with strict input validation rules to filter out malicious scripts before they reach the application.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The high severity of this vulnerability, combined with the existence of a proof-of-concept, necessitates immediate action. Administrators must prioritize updating to version 3.7.4 to eliminate the risk of remote code execution.

More siyuan-note CVEs