rootpwn

critical · CVSS v3 7.6 · CVSS v4 7.2

CVE-2026-100642

SiYuan versions before 3.8.4 are vulnerable to a CSRF flaw that allows attackers to gain administrative privileges via loopback requests. Th

Overview

SiYuan versions before 3.8.4 are vulnerable to a CSRF flaw that allows attackers to gain administrative privileges via loopback requests. The flaw bypasses Origin header checks in the lock‑screen authentication flow, enabling malicious web pages to trigger privileged actions from a victim’s browser. This can lead to unauthorized configuration changes and process termination.

Description

SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-screen pass-through branch that grants administrator access to loopback requests without validating Origin headers. Attackers can craft malicious web pages that force victims to terminate the kernel process, read workspace configuration and proxy settings, and trigger administrative actions via zero-credential cross-origin requests from the victim's browser.

Impact

The vulnerability allows attackers to elevate privileges to administrator, compromising confidentiality of workspace data, integrity of configuration, and availability by terminating kernel processes. Administrators and users of affected SiYuan installations are at risk of unauthorized configuration changes and service disruption.

Remediation

Apply the official patch by upgrading to SiYuan v3.8.4 or later. If upgrading is not immediately possible, block local loopback requests to the application, enforce strict Origin header validation, disable the lock‑screen pass‑through feature, and restrict the application’s network access via firewall rules. Monitor for abnormal administrative actions and audit logs for signs of exploitation.

Risk context

This is a critical‑severity vulnerability with a CVSS v3 score of 7.6. The lack of an EPSS score indicates no current predictive data, but the high severity and potential for privilege escalation warrant prompt remediation.

Affected products

  • SiYuan v2.1.0
  • SiYuan v2.1.1
  • SiYuan v2.2.0
  • SiYuan v3.0.0
  • SiYuan v3.1.0
  • SiYuan v3.5.0
  • SiYuan v3.7.0
  • SiYuan v3.8.3

Scores

Severity
critical
CVSS v2
9
CVSS v3
7.6
CVSS v4
7.2
EPSS
—

CSRF SiYuan critical admin-privilege lock-screen origin-header cross-origin vulnerability

← All CVEs