CVE-2026-100642 Details
Description
SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-screen pass-through branch that grants administrator access to loopback requests without validating Origin headers. Attackers can craft malicious web pages that force victims to terminate the kernel process, read workspace configuration and proxy settings, and trigger administrative actions via zero-credential cross-origin requests from the victim's browser.
A cross-site request forgery vulnerability has been identified in SiYuan versions 2.1.0 prior to 3.8.4. The issue resides in the CheckAuth lock-screen pass-through branch, which allows loopback requests to gain administrator access without validating Origin headers. This vulnerability enables attackers to create malicious web pages that can force victims to terminate the SiYuan kernel process, access unredacted workspace and proxy information, and execute administrative actions through cross-origin requests from the victim's browser.
Users can update to SiYuan version 3.8.4 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-346 | Origin Validation Error | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SiYuan | >= 2.1.0, < 3.8.4 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 26, 2026 | New CVE Received | [email protected] |
Volerion