THREAT OPS › Threat News › [NVD] CVE-2026-73043 (CRITICAL 9.0) — SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and JavaScript into template calculation
[NVD] CVE-2026-73043 (CRITICAL 9.0) — SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and JavaScript into template calculation
CVE-2026-73043 CVSS: 9.0 CRITICAL Published: 2026-08-15T22:16:54.200
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and JavaScript into template calculations that execute in the desktop client renderer with
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-73043cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73043