CVE-2026-75917 | SiYuan Note up to 3.7.3 Hover Tooltip Generation app/src/util/pathName.ts getLeaf/movePathTo bookmark/alias/memo/alternate name field cross site scripting

SecurityVulns

A vulnerability identified as problematic has been detected in SiYuan Note SiYuan up to 3.7.3. Affected is the function getLeaf/movePathTo of the file app/src/util/pathName.ts of the component Hover Tooltip Generation. This manipulation of the argument bookmark/alias/memo/alternate name field causes cross site scripting.

This vulnerability appears as CVE-2026-75917. The attack may be initiated remotely. There is no available exploit.

You should upgrade the affected component.VulDB Recent EntriesRead More