All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-74800
CRITICALpublished 2026-08-17 11:16 UTC · 22 hours ago · modified 2026-08-17 16:17 UTC
9.4
CVSS / 10
// description
SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can upload HTML files as assets and execute scripts with full kernel API access when the workspace owner opens the asset link.
// weaknesses (CWE)
- CWE-79