PT-2026-99313 · Siyuan · Siyuan
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
SiYuan versions 2.1.0 through 3.8.3
Description
A cross-site request forgery issue exists in the CheckAuth lock-screen pass-through branch. The system grants administrator access to loopback requests without validating Origin headers, which are HTTP headers that indicate where a request originates. This allows attackers to use malicious web pages to force victims to terminate the kernel process, read workspace configuration and proxy settings, and execute administrative actions through zero-credential cross-origin requests from the browser.
Recommendations
Update SiYuan to version 3.8.4 or later.
Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan