CVE-2026-73043Disclosure

LOWCVSS 9.4 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and JavaScript into template calculations that execute in the desktop client renderer with Node integration enabled, allowing arbitrary code execution when the database is opened.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-08-16: 4Patch / Workaround · 2026-08-16: 2Technical Details · 2026-08-16: 408-16
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • HOL@HashgraphOnline
    Disclosure

    BREAKING: CVE-2026-73043 turns a low-privilege SiYuan database Template calculation into desktop OS command execution. The server stores text/template output verbatim. The Electron client later inserts it with innerHTML, bypassing the sanitizer used on the equivalent template-column path. CVSS 9.0 Critical.

    Post summary

    CVE-2026-73043 reveals a critical template injection flaw in SiYuan that enables desktop OS command execution, with a CVSS score of 9.0.

    10000451
    15.9K followersView on X
  • ADK Cyber@ADKCyber
    General

    SiYuan < v3.7.4 has CVSS 9.4 RCE in unsanitized Go templates. Verify usage and update: https://nvd.nist.gov/vuln/detail/CVE-2026-73043 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/eT08oUTPRu

    Post summary

    The post highlights a high‑severity RCE in SiYuan versions below 3.7.4, advises users to verify usage and apply updates, but offers no exploit code or evidence of active exploitation.

    0000045
    93 followersView on X
  • HOL@HashgraphOnline
    Patch

    Affected: SiYuan <3.7.4. Fixed in 3.7.4; current stable is 3.8.0. Because the desktop renderer has Node integration enabled, injected script can reach Node built-ins such as child_process. Technical details and remediation: https://hol.org/blog/cve-2026-73043-siyuan-template-calculation-rce

    Post summary

    SiYuan versions <3.7.4 are vulnerable to remote code execution via Node integration; the issue is fixed in version 3.7.4 and the latest stable 3.8.0 is unaffected.

    0000093
    15.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-73043 Remote Code Execution in SiYuan v3.7.4 via Unsanitized Te... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-73043 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    CVE-2026-73043 discloses a remote code execution flaw in SiYuan v3.7.4 due to unsanitized input; no PoC, exploit code, patch, or active exploitation is mentioned.

    0000092
    4.1K followersView on X

Explore more