PT-2026-99317 · Siyuan · Siyuan

·

CVE-2026-100646

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.8.4
Description Authentication guards CheckAuth() in kernel/model/session.go and IsSessionOriginAllowed() in kernel/util/net.go fail open when the HTTP Origin header is absent. This occurs because the system incorrectly assumes all browser-initiated cross-site requests include an Origin header. Since browsers omit this header during cross-site top-level GET navigations and no-cors GET subresource loads, and the session cookie uses SameSite=Lax, a cross-site GET request from an attacker-controlled page can be granted RoleAdministrator privileges. This affects both default installations and password-protected instances with active sessions. When combined with content-type sniffing on the '/api/network/proxy' endpoint, an unauthenticated remote attacker can serve malicious HTML under the SiYuan origin, execute arbitrary scripts, invoke administrator APIs, and exfiltrate the persistent kernel API token.
Recommendations Update to version 3.8.4.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100646
GHSA-2W6Q-WGC8-Q743

Affected Products

Siyuan