CVE-2026-73041Disclosure

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js access when a user opens an annotated PDF.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-16); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-16: 1Mentions · 2026-08-27: 1Technical Details · 2026-08-16: 1Technical Details · 2026-08-27: 108-1608-27
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-161
Disclosure1
2026-08-271
General1
Full discourse2 posts
  • SECNORA®@secnorainfosec
    General

    🚨 CVE-2026-73041 - CVSS Score 9.4 (Critical): The PDF That Travels With Its Own RCE Five unescaped PDF annotation fields in SiYuan create a path from stored XSS to potential RCE. 🔗 Read full blog: https://secnora.com/blog/cve-2026-73041-siyuan-pdf-annotation-rce/

    Post summary

    The blog highlights a critical PDF RCE vulnerability in SiYuan via unescaped annotation fields, but no exploit code, patch, or active exploitation is mentioned.

    0001043
    75 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-73041 SiYuan v3.7.4 Annotation Field Vulnerability Enables Script Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-73041

    Post summary

    The post announces CVE-2026-73041, a script‑execution vulnerability in SiYuan v3.7.4’s annotation field, but offers no PoC, exploit code, or patch information.

    00100290
    4.1K followersView on X

Explore more