Threat intelligence dashboard
CVE-2026-100635high

SiYuan before v3.8.4 Authentication Bypass via Plaintext Session Cookie

SiYuan before v3.8.4 contains an authentication bypass vulnerability in the publish service where session cookies are issued without Secure or SameSite attributes over plaintext HTTP connections. An on-path attacker can observe a valid publish-visitor-session-id cookie from a Basic Auth exchange and replay it to access authenticated publish endpoints without knowing the account password.

Risk score

8.2

CVSS 4.0

Vendor
siyuan-note
Product
siyuan
CWE
CWE-319
Published
Sep 26, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

siyuan

siyuan-note

Version / rangeStatusType
0 to before 3.8.4affectedsemver
3.8.4unaffectedsemver

Technical metrics

8.2

CVSS 4.0

Severity
high
Source
VulnCheck
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

5.9

CVSS 3.1

Severity
medium
Source
VulnCheck
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N