CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-73044

criticalCVSS 9covered by 1 sourcefirst seen 2026-08-15
SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious payloads through the setAttrViewColWidth API that break out of style attributes and inject event handlers on every table cell, executing arbitrary code in the Electron renderer with Node integration enabled.

⚡ Watch CVE-2026-73044

Get an email if CVE-2026-73044 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-73044

CVE.org record

Embed the live status

CVE-2026-73044 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-73044 status](https://www.csirts.com/badge/CVE-2026-73044)](https://www.csirts.com/cve/CVE-2026-73044)