Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100646— SiYuan before v3.8.4 Authentication Bypass via Missing Origin Header

Quick assessment

Affected
siyuan-note siyuan
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

思源笔记(SiYuan)是一个自托管的个人知识管理系统。在 3.8.3 及更早版本中,内核的身份验证守卫机制(具体为 中的 函数和 中的 函数)存在“失败开放”(fail-open)漏洞。该漏洞源于一个错误假设,即认为所有由浏览器发起的跨站请求都会携带 HTTP Origin 头。然而,当 Origin 头缺失时,这些守卫机制未能正确拒绝请求,而是默认允许通过。 由于浏览器在以下场景中会省略 Origin 头: 跨站顶级 GET 导航; 非 CORS 模式的 GET 子资源加载; 并且会话 Cookie 设置了 属

CVSS 8.1 · High EPSS 0.19% · P8
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100646

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SiYuan before v3.8.4 Authentication Bypass via Missing Origin Header
Source: CVE Program / CVE List V5
Vulnerability Description
SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3, the kernel's authentication guards (CheckAuth in kernel/model/session.go and IsSessionOriginAllowed in kernel/util/net.go) fail open when the HTTP Origin header is absent, on the incorrect assumption that any browser-initiated cross-site request carries an Origin. Because browsers omit Origin on cross-site top-level GET navigations and no-cors GET subresource loads — and the session cookie is SameSite=Lax — a single cross-site GET issued from any attacker-controlled web page is granted RoleAdministrator, both on default installations with no access-authorization code and on password-protected instances with a live session. Combined with content-type sniffing on the /api/network/proxy endpoint, which allows attacker-controlled HTML to be served under SiYuan's own origin, this permits an unauthenticated remote attacker to execute arbitrary script in the SiYuan origin (http://127.0.0.1:6806), invoke administrator APIs, and exfiltrate the persistent kernel API token. This issue is fixed in version 3.8.4.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
源验证错误
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
siyuan-note siyuan 0 ~ 3.8.4 -

II. Public POCs for CVE-2026-100646

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100646

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100646 (1)

Other References for CVE-2026-100646 (1)

Same Patch Batch · siyuan-note · 2026-09-26 · 14 CVEs total

CVE-2026-100639 8.8 HIGH SiYuan before v3.8.4 Cross-Site Scripting via Kramdown IAL
CVE-2026-100645 8.0 HIGH SiYuan 3.7.0 before 3.8.4 Stored XSS via Gallery Kanban
CVE-2026-100643 8.0 HIGH SiYuan before v3.8.4 Stored XSS via Attribute View textarea
CVE-2026-100641 8.0 HIGH SiYuan before v3.8.4 Stored XSS via Unescaped Flashcard Content
CVE-2026-100642 7.6 HIGH SiYuan v2.1.0 before v3.8.4 Cross-Site Request Forgery via CheckAuth
CVE-2026-100637 7.6 HIGH SiYuan before v3.8.4 Path Traversal via checkoutRepo sessionID
CVE-2026-100638 7.6 HIGH SiYuan before v3.8.4 Path Traversal via setNotebookIcon
CVE-2026-100636 7.6 HIGH SiYuan before v3.8.4 Path Traversal via exportBrowserHTML folder
CVE-2026-100644 7.5 HIGH SiYuan before v3.8.4 SQL Injection via dailyNoteSavePath
CVE-2026-100633 6.5 MEDIUM SiYuan 3.8.0 through 3.8.3 Path Traversal via MCP File Operations
CVE-2026-100635 5.9 MEDIUM SiYuan before v3.8.4 Authentication Bypass via Plaintext Session Cookie
CVE-2026-100634 4.7 MEDIUM SiYuan before v3.8.4 Missing Authorization via siyuan-send-windows
CVE-2026-100640 4.7 MEDIUM SiYuan before v3.8.4 Clipboard Data Disclosure via IPC

IV. Related Vulnerabilities

V. Comments for CVE-2026-100646

No comments yet


Leave a comment