EXPOSURES › CVE-2026-73053
CVE-2026-73053
CRITICAL
DETAIL
SourceNVD · cve
Published2026-08-15
CVSS9.0
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-73053 ↗
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
DESCRIPTION
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with Node integration enabled, achieving arbitrary code execution on the host system.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.