Cross-Site Request Forgery Vulnerability in SiYuan by SiYuan Note
CVE-2026-74867
2.3LOW
What is CVE-2026-74867?
SiYuan versions prior to 3.7.4 exhibit a vulnerability in their CheckAuth() function, which fails to validate Origin/Referer headers and does not apply SameSite attributes to session cookies. This weakness allows malicious actors to create harmful web pages that execute unauthorized actions on behalf of users who are authenticated. By exploiting this flaw, attackers can leverage the default SameSite policies of web browsers rather than relying on server-side security measures, posing significant risks to user data and actions.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
