CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-73043

criticalCVSS 9covered by 1 sourcefirst seen 2026-08-15
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and JavaScript into template calculations that execute in the desktop client renderer with Node integration enabled, allowing arbitrary code execution when the database is opened.

⚡ Watch CVE-2026-73043

Get an email if CVE-2026-73043 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-73043

CVE.org record

Embed the live status

CVE-2026-73043 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-73043 status](https://www.csirts.com/badge/CVE-2026-73043)](https://www.csirts.com/cve/CVE-2026-73043)