PT-2026-99313 · Siyuan · Siyuan

·

CVE-2026-100642

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions SiYuan versions 2.1.0 through 3.8.3
Description A cross-site request forgery issue exists in the CheckAuth lock-screen pass-through branch. The system grants administrator access to loopback requests without validating Origin headers, which are HTTP headers that indicate where a request originates. This allows attackers to use malicious web pages to force victims to terminate the kernel process, read workspace configuration and proxy settings, and execute administrative actions through zero-credential cross-origin requests from the browser.
Recommendations Update SiYuan to version 3.8.4 or later.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100642
GHSA-9GPJ-3RM3-X42M

Affected Products

Siyuan