logo

SiYuan Column Width API Stored XSS (CVE-2026-73044)

ID: 03be49ea-fdc3-5cf5-8fa2-4fbb717e75c1

STIX ID: report--03be49ea-fdc3-5cf5-8fa2-4fbb717e75c1

Feed Name: CosmicBytez Labs

Threat Score
72/100

Date Published: 2026-08-16

Date Updated: 2026-08-17

...
...

**CVE-2026-73044 — Stored XSS in SiYuan (< 3.7.4):** A critical (CVSS 9.0) stored cross-site scripting vulnerability in SiYuan's setAttrViewColWidth API lets an authenticated attacker store a malicious width string that breaks out of a style attribute and injects event handlers, enabling arbitrary JavaScript execution in any user's browser who views the affected table; remediation is to upgrade to SiYuan v3.7.4 and apply access and data-audit mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.