PT-2026-99311 · Siyuan · Siyuan

·

CVE-2026-100640

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

8.6

High

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.8.4
Description An authorization omission exists in the siyuan-get IPC handler. This allows remote-kernel renderers to access native clipboard formats by invoking the clipboardReadMathML(), clipboardReadOffice(), and clipboardReadWPS() commands with matching plaintext. Attackers who control remote renderer content can obtain MathML formulas, Office bytes, and WPS bytes from the local clipboard during user-mediated paste operations.
Recommendations Update to version 3.8.4 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100640
GHSA-MJMM-HGMC-M7QF

Affected Products

Siyuan