PT-2026-99305 · Siyuan · Siyuan

·

CVE-2026-100634

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.8.4
Description The Electron main process in app/electron/main.js fails to validate the sender or restrict recipients within the 'siyuan-send-windows' IPC handler. The handler ignores the event.sender and forwards any received payload to all windows returned by BrowserWindow.getAllWindows(), including those from different opened workspaces. An attacker-controlled remote kernel can send a payload with the cmd variable set to "lockscreenByMode", which triggers the lockScreen() function in sibling workspace windows where lockScreenMode is set to 1. This can be used to repeatedly lock unrelated local workspace windows, resulting in a limited denial of service.
Recommendations Update SiYuan to version 3.8.4 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100634
GHSA-WXP7-XPQ8-8XPM

Affected Products

Siyuan