CVE-2026-100640 Details
Description
SiYuan before v3.8.4 contains an authorization omission in the siyuan-get IPC handler that allows remote-kernel renderers to access native clipboard formats by invoking clipboardReadMathML, clipboardReadOffice, and clipboardReadWPS commands with matching plaintext. Attackers controlling remote renderer content can obtain MathML formulas, Office bytes, and WPS bytes from local clipboard during user-mediated paste operations.
A vulnerability exists in SiYuan versions prior to 3.8.4, where an authorization flaw in the 'siyuan-get' IPC handler allows remote-kernel renderers to access native clipboard data. By using the 'clipboardReadMathML', 'clipboardReadOffice', and 'clipboardReadWPS' commands with corresponding plaintext, attackers can retrieve MathML formulas, Office bytes, and WPS bytes from the local clipboard during user-initiated paste actions. This issue arises because these commands bypass the remote-sender authorization check, enabling the extraction of sensitive clipboard contents through a privileged IPC channel.
Users can update to SiYuan version 3.8.4 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/siyuan-note/siyuan/security/advisories/GHSA-mjmm-hgmc-m7qf | [email protected] | AdvisoryExploitTechnical AnalysisVendor |
| https://www.vulncheck.com/advisories/siyuan-before-3.8.4-clipboard-data-disclosure-via-ipc | [email protected] | AdvisoryVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SiYuan | <pinned-revision-8641553a1f07374001902d3ce773285db1292b2d> |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 26, 2026 | New CVE Received | [email protected] |
Volerion