Siyuan · Siyuan · CVE-2026-100646
**Name of the Vulnerable Software and Affected Versions**
SiYuan versions prior to 3.8.4
**Description**
Authentication guards `CheckAuth()` in `kernel/model/session.go` and `IsSessionOriginAllowed()` in `kernel/util/net.go` fail open when the HTTP Origin header is absent. This occurs because the system incorrectly assumes all browser-initiated cross-site requests include an Origin header. Since browsers omit this header during cross-site top-level GET navigations and no-cors GET subresource loads, and the session cookie uses SameSite=Lax, a cross-site GET request from an attacker-controlled page can be granted RoleAdministrator privileges. This affects both default installations and password-protected instances with active sessions. When combined with content-type sniffing on the '/api/network/proxy' endpoint, an unauthenticated remote attacker can serve malicious HTML under the SiYuan origin, execute arbitrary scripts, invoke administrator APIs, and exfiltrate the persistent kernel API token.
**Recommendations**
Update to version 3.8.4.