---
id: CVE-2026-73041
title: >-
  SiYuan versions before v3.7.4 fail to validate or escape annotation fields
  written to disk by the setFileAnnotation endpoint
summary: >-
  SiYuan versions before v3.7.4 fail to validate or escape annotation fields
  written to disk by the setFileAnnotation endpoint. Attackers can inject
  malicious markup into annotation fields that execute as script in the PDF
  renderer with fu…
severity: critical
cvss: 9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-79
published: '2026-08-15'
updated: '2026-08-15'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73041'
references:
  - url: >-
      https://github.com/siyuan-note/siyuan/security/advisories/GHSA-fqpw-c3pj-w8g9
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/siyuan-before-remote-code-execution-via-pdf-annotations
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-08-16T13:39:03.922Z'
epss: 0.00234
epssPercentile: 0.14557
---

## Overview

SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js access when a user opens an annotated PDF.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
