PT-2026-50413 · Siyuan · Siyuan
CVE-2026-54069
·
Published
2026-06-17
·
Updated
2026-07-30
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.7.0
Description
The kernel HTTP server unconditionally trusts all chrome-extension:// origins, granting RoleAdministrator access to every installed browser extension without authentication. When combined with the default empty
AccessAuthCode on desktop installations, any Chrome or Chromium extension can make fully authenticated admin API calls to the kernel at '127.0.0.1:6806'. This allows for data exfiltration, stored XSS (Cross-Site Scripting, a method of injecting malicious scripts into web pages) injection, and configuration tampering.Recommendations
Update to version 3.7.0.
Exploit
Fix
DoS
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan