CVE-2026-100635
5.9 MEDIUMpublic exploit availablePublished 2026-09-26 · Updated 2026-09-28
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
SiYuan before v3.8.4 contains an authentication bypass vulnerability in the publish service where session cookies are issued without Secure or SameSite attributes over plaintext HTTP connections. An on-path attacker can observe a valid publish-visitor-session-id cookie from a Basic Auth exchange and replay it to access authenticated publish endpoints without knowing the account password.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-319
Public exploit & PoC references
- https://github.com/siyuan-note/siyuan/commit/79d47867b106467c951475a9193455b48d1f3682
- https://github.com/siyuan-note/siyuan/commit/ff4d215f78a8d6e6db6052be18b5f9f4db9c7d68
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-7j37-4gq6-wm7m
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-7j37-4gq6-wm7m
All references
- https://github.com/siyuan-note/siyuan/commit/79d47867b106467c951475a9193455b48d1f3682
- https://github.com/siyuan-note/siyuan/commit/ff4d215f78a8d6e6db6052be18b5f9f4db9c7d68
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-7j37-4gq6-wm7m
- https://www.vulncheck.com/advisories/siyuan-before-3.8.4-authentication-bypass-via-plaintext-session-cookie
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-7j37-4gq6-wm7m
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2025-36421
- LOWCVE-2026-101057PoC
- HIGHCVE-2026-18134
- HIGHCVE-2026-18176
- UNSCOREDCVE-2026-54586PoC
- UNSCOREDCVE-2026-73174
- MEDIUMCVE-2026-82585PoC
- UNSCOREDCVE-2026-85628
Related by shared AI tags and CWE weakness class. Browse the full archive.