PT-2026-71251 · Siyuan · Siyuan
CVSS v3.1
8.0
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.7.4
Description
An authentication bypass exists in the kernel's
CheckAuth() function. The system grants the RoleAdministrator role to any request where the RemoteAddr is the loopback address (127.0.0.1) for specific endpoints, including /api/system/exit, getNetwork, getWorkspaceInfo, /assets/*, and /export/*. This bypass occurs outside the access authentication code gate, meaning it remains effective even if an access auth code is configured. When a fixed-port reverse proxy forwards requests to the kernel over loopback without an authentication token and without configured trusted proxies, the kernel perceives the RemoteAddr as 127.0.0.1. If this proxy is bound to a network interface, a remote unauthenticated attacker could potentially obtain administrator access to the affected endpoints, although this specific remote forwarding behavior has only been identified via code inspection and not reproduced end-to-end.Recommendations
Update to version 3.7.4 or later.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan