Skip to content
COOEY

EXPOSURES › CVE-2026-73053

CVE-2026-73053

CRITICAL
DETAIL
SourceNVD · cve Published2026-08-15 CVSS9.0 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-73053 ↗

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with Node integration enabled, achieving arbitrary code execution on the host system.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.