Cross-Site Request Forgery in SiYuan Versions from v2.1.0 to v3.8.4
CVE-2026-100642

7.2HIGH

Key Information:

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100642?

Versions of SiYuan from v2.1.0 to v3.8.4 are susceptible to a cross-site request forgery (CSRF) vulnerability. This flaw resides in the CheckAuth lock-screen pass-through functionality, which fails to properly validate Origin headers for loopback requests. By exploiting this vulnerability, an attacker can create malicious web pages designed to manipulate the victim's browser into making unrestricted administrative requests. This may lead to compromising workspace configurations, revealing sensitive proxy settings, and initiating unauthorized actions without requiring user credentials.

Affected Version(s)

siyuan 2.1.0 < 3.8.4

siyuan 3.8.4

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yanhaoxi
.