CVE-2026-74800: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in siyuan-note siyuan
CVE-2026-74800 is a critical stored cross-site scripting (XSS) vulnerability in SiYuan note-taking software versions prior to 3.7.4. The issue arises because the software fails to set the Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets. Authenticated attackers can exploit this by uploading malicious HTML files as assets, which execute scripts with full kernel API access when the workspace owner opens the asset link.
AI Analysis
Technical Summary
SiYuan versions before 3.7.4 do not set the Content-Disposition and X-Content-Type-Options HTTP headers when serving arbitrary file assets. This improper neutralization of input during web page generation allows authenticated attackers to upload HTML files containing malicious scripts. When the workspace owner opens the link to such an asset, the scripts execute with full kernel API access, constituting a stored cross-site scripting vulnerability.
Potential Impact
An authenticated attacker can upload malicious HTML files that execute scripts with full kernel API access in the context of the workspace owner. This can lead to severe compromise of the user's environment, including unauthorized actions and potential system control. The vulnerability has a CVSS 4.0 score of 9.4, indicating critical severity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vulnerability affects versions prior to 3.7.4, upgrading to version 3.7.4 or later is likely recommended once official fixes are published. Until then, restrict asset uploads to trusted users and avoid opening untrusted asset links.
CVE-2026-74800: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in siyuan-note siyuan
Description
CVE-2026-74800 is a critical stored cross-site scripting (XSS) vulnerability in SiYuan note-taking software versions prior to 3.7.4. The issue arises because the software fails to set the Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets. Authenticated attackers can exploit this by uploading malicious HTML files as assets, which execute scripts with full kernel API access when the workspace owner opens the asset link.
CVSS v4.0
Score 9.4critical
Affected software
siyuan-note
siyuan
pkg:github/siyuan-note/siyuanRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
SiYuan versions before 3.7.4 do not set the Content-Disposition and X-Content-Type-Options HTTP headers when serving arbitrary file assets. This improper neutralization of input during web page generation allows authenticated attackers to upload HTML files containing malicious scripts. When the workspace owner opens the link to such an asset, the scripts execute with full kernel API access, constituting a stored cross-site scripting vulnerability.
Potential Impact
An authenticated attacker can upload malicious HTML files that execute scripts with full kernel API access in the context of the workspace owner. This can lead to severe compromise of the user's environment, including unauthorized actions and potential system control. The vulnerability has a CVSS 4.0 score of 9.4, indicating critical severity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vulnerability affects versions prior to 3.7.4, upgrading to version 3.7.4 or later is likely recommended once official fixes are published. Until then, restrict asset uploads to trusted users and avoid opening untrusted asset links.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-16T12:59:42.223Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a82f001bf8831d539c482c9
Added to database: 08/17/2026, 11:26:57 UTC
Last enriched: 08/24/2026, 13:26:42 UTC
Last updated: 10/02/2026, 14:46:10 UTC
Views: 54
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.