Authentication Bypass in SiYuan Personal Knowledge Management System
CVE-2026-100646
What is CVE-2026-100646?
The SiYuan personal knowledge management system, prior to version 3.8.4, exhibits a significant vulnerability due to the failure of its authentication guards to properly validate the HTTP Origin header. This flaw allows attackers to exploit cross-site request patterns that do not include an Origin, granting them unauthorized administrative access. By leveraging this weakness, a malicious user can issue cross-site GET requests from an attacker-controlled web page, not only gaining access to administrative APIs but also enabling the execution of arbitrary scripts within SiYuan's origin context. Furthermore, the vulnerability is compounded by content-type sniffing vulnerabilities within its API, permitting the delivery of attacker-controlled HTML content. Users are strongly advised to upgrade to version 3.8.4 or later to mitigate these risks.
Affected Version(s)
siyuan 0 < 3.8.4
siyuan 3.8.4
