โ† Back to Dashboard

CVE-2026-74800

CRITICAL NVD
CVSS Score
9.0
Severity
CRITICAL
Source
NVD
Published
Aug 17, 2026
Description

SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can upload HTML files as assets and execute scripts with full kernel API access when the workspace owner opens the asset link.

View Full Details โ† Back