PT-2026-76603 · Siyuan · Siyuan

·

CVE-2026-74867

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.7.4
Description A cross-site request forgery issue exists in the session-cookie authentication branch of the CheckAuth() function. The system fails to perform Origin or Referer validation and does not set an explicit SameSite attribute on session cookies. This allows attackers to create malicious web pages that execute unauthorized actions on behalf of authenticated users by submitting requests with valid session cookies, exploiting the reliance on default browser SameSite policies instead of server-side protections.
Recommendations Update to version 3.7.4 or later.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74867

Affected Products

Siyuan