Ghostwire

CVE-2026-74801: SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line arguments for the...

HIGH CVSS 0.0

Published: August 17, 2026 | Last Modified: August 17, 2026

Description

SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line arguments for the elevated elevator.exe helper process. Attackers can create a malicious workspace directory with command metacharacters in its path and trigger the Microsoft Defender exclusion flow to execute arbitrary commands with administrator privileges after UAC approval.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References