PT-2026-76603 · Siyuan · Siyuan
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.7.4
Description
A cross-site request forgery issue exists in the session-cookie authentication branch of the
CheckAuth() function. The system fails to perform Origin or Referer validation and does not set an explicit SameSite attribute on session cookies. This allows attackers to create malicious web pages that execute unauthorized actions on behalf of authenticated users by submitting requests with valid session cookies, exploiting the reliance on default browser SameSite policies instead of server-side protections.Recommendations
Update to version 3.7.4 or later.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan