Cross-Site Request Forgery Vulnerability in SiYuan by SiYuan Note
CVE-2026-74867

2.3LOW

Key Information:

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-74867?

SiYuan versions prior to 3.7.4 exhibit a vulnerability in their CheckAuth() function, which fails to validate Origin/Referer headers and does not apply SameSite attributes to session cookies. This weakness allows malicious actors to create harmful web pages that execute unauthorized actions on behalf of users who are authenticated. By exploiting this flaw, attackers can leverage the default SameSite policies of web browsers rather than relying on server-side security measures, posing significant risks to user data and actions.

Affected Version(s)

siyuan 0 < 3.7.4

siyuan 3.7.4

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

alham-rizvi
l1nuxkid
.