Cross-Site Request Forgery in SiYuan Versions from v2.1.0 to v3.8.4
CVE-2026-100642
7.2HIGH
What is CVE-2026-100642?
Versions of SiYuan from v2.1.0 to v3.8.4 are susceptible to a cross-site request forgery (CSRF) vulnerability. This flaw resides in the CheckAuth lock-screen pass-through functionality, which fails to properly validate Origin headers for loopback requests. By exploiting this vulnerability, an attacker can create malicious web pages designed to manipulate the victim's browser into making unrestricted administrative requests. This may lead to compromising workspace configurations, revealing sensitive proxy settings, and initiating unauthorized actions without requiring user credentials.
Affected Version(s)
siyuan 2.1.0 < 3.8.4
siyuan 3.8.4
