PT-2026-99317 · Siyuan · Siyuan
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.8.4
Description
Authentication guards
CheckAuth() in kernel/model/session.go and IsSessionOriginAllowed() in kernel/util/net.go fail open when the HTTP Origin header is absent. This occurs because the system incorrectly assumes all browser-initiated cross-site requests include an Origin header. Since browsers omit this header during cross-site top-level GET navigations and no-cors GET subresource loads, and the session cookie uses SameSite=Lax, a cross-site GET request from an attacker-controlled page can be granted RoleAdministrator privileges. This affects both default installations and password-protected instances with active sessions. When combined with content-type sniffing on the '/api/network/proxy' endpoint, an unauthenticated remote attacker can serve malicious HTML under the SiYuan origin, execute arbitrary scripts, invoke administrator APIs, and exfiltrate the persistent kernel API token.Recommendations
Update to version 3.8.4.
Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan