π¨ CVE-2026-100629
Capgo (capgo.app backend) before 12.127.5 contains an authorization flaw in the PATCH /private/role_bindings/:binding_id endpoint. The handler verifies that the newly assigned role's priority rank does not exceed the caller's own rank, but β unlike the DELETE handler β it never checks the rank of the role currently bound to the target binding. An authenticated user holding the org_admin role (rank 90) can therefore change an org_super_admin binding (rank 95) to a lower-privileged role such as org_member (rank 75). Because the prevent_last_super_admin_binding_delete database trigger fires only BEFORE DELETE and not on UPDATE, an org_admin can demote every org_super_admin, leaving the organization with no super administrator. The issue is fixed in 12.127.5.
π@cveNotify
Capgo (capgo.app backend) before 12.127.5 contains an authorization flaw in the PATCH /private/role_bindings/:binding_id endpoint. The handler verifies that the newly assigned role's priority rank does not exceed the caller's own rank, but β unlike the DELETE handler β it never checks the rank of the role currently bound to the target binding. An authenticated user holding the org_admin role (rank 90) can therefore change an org_super_admin binding (rank 95) to a lower-privileged role such as org_member (rank 75). Because the prevent_last_super_admin_binding_delete database trigger fires only BEFORE DELETE and not on UPDATE, an org_admin can demote every org_super_admin, leaving the organization with no super administrator. The issue is fixed in 12.127.5.
π@cveNotify
GitHub
R - PATCH /role_bindings Missing Existing-Role Rank Check Allows org_admin to Demote org_super_admin
## Summary
The `PATCH /private/role_bindings/:binding_id` endpoint checks whether the *new* role's priority rank is within the caller's privilege level, but fails to check whether the *exi...
The `PATCH /private/role_bindings/:binding_id` endpoint checks whether the *new* role's priority rank is within the caller's privilege level, but fails to check whether the *exi...
π¨ CVE-2026-100630
AVideo contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an inline onclick JavaScript string. Attackers with video upload permission can store HTML entity-encoded payloads that bypass isValidURL() validation and are decoded by the browser to break out of the JavaScript string, executing arbitrary code in any visitor's session including administrators.
π@cveNotify
AVideo contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an inline onclick JavaScript string. Attackers with video upload permission can store HTML entity-encoded payloads that bypass isValidURL() validation and are decoded by the browser to break out of the JavaScript string, executing arbitrary code in any visitor's session including administrators.
π@cveNotify
GitHub
Stored XSS in video trailer1 field via HTML-entity bypass of isValidURL()
### Summary
The video `trailer1` field is rendered unsanitized inside an inline `onclick` JavaScript string in the Gallery/CustomizeAdvanced trailer button. Input validation relies on `isValidUR...
The video `trailer1` field is rendered unsanitized inside an inline `onclick` JavaScript string in the Gallery/CustomizeAdvanced trailer button. Input validation relies on `isValidUR...
π¨ CVE-2026-100631
Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-alpha.9, the device token deduplication logic for installation records does not validate the type of client-supplied installation fields before using them to build database queries. An unauthenticated remote attacker who knows only the public application ID can submit non-string values in these fields to inject query operators, causing the deduplication cleanup β which runs with elevated privileges before class-level permissions are evaluated β to delete every device registration in the application or an attacker-chosen subset of them. No account, session token, master key, or user interaction is required. Deleted registrations cannot be recovered on the server, so push notifications cannot be delivered until every client re-registers. Any deployment that exposes the REST API to clients and uses push notifications is affected in its default configuration. Versions 8.6.90 and 9.10.1-alpha.9 fix the issue by rejecting non-string values with a client error and by scoping the deduplication cleanup to the calling application. No workaround other than upgrading is available.
π@cveNotify
Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-alpha.9, the device token deduplication logic for installation records does not validate the type of client-supplied installation fields before using them to build database queries. An unauthenticated remote attacker who knows only the public application ID can submit non-string values in these fields to inject query operators, causing the deduplication cleanup β which runs with elevated privileges before class-level permissions are evaluated β to delete every device registration in the application or an attacker-chosen subset of them. No account, session token, master key, or user interaction is required. Deleted registrations cannot be recovered on the server, so push notifications cannot be delivered until every client re-registers. Any deployment that exposes the REST API to clients and uses push notifications is affected in its default configuration. Versions 8.6.90 and 9.10.1-alpha.9 fix the issue by rejecting non-string values with a client error and by scoping the deduplication cleanup to the calling application. No workaround other than upgrading is available.
π@cveNotify
GitHub
Unauthenticated deletion of installation records via operator injection in device token deduplication
### Impact
An unauthenticated attacker can delete every device registration in a Parse Server application, or an arbitrary attacker-chosen subset of them, using ordinary HTTP requests. Only the ...
An unauthenticated attacker can delete every device registration in a Parse Server application, or an arbitrary attacker-chosen subset of them, using ordinary HTTP requests. Only the ...
π¨ CVE-2026-100632
Parse Server is an open-source backend server. In versions >= 9.0.0 and < 9.10.1-alpha.8, and in versions < 8.6.89, LiveQuery evaluates the protectedFields class-level permission against an incompletely resolved caller identity: the subscriber's roles are not resolved, and when a subscription does not supply its own session token the event payload is redacted against an anonymous identity even though the read was authorized against the connected user. As a result, field masks defined for a role, for authenticated users, or for a specific user are not applied, so an authenticated subscriber can receive field values that the REST API correctly withholds and can use a masked field to filter or watch a subscription. Only classes with LiveQuery enabled that define protectedFields under a role:, authenticated, or per-user group are affected; masks under the public (*) group are applied correctly. The issue is fixed in 9.10.1-alpha.8 and 8.6.89. As a workaround, additionally define the affected field masks under the public (*) group, or disable LiveQuery for classes whose class-level permissions rely on role-scoped, authenticated, or per-user protectedFields groups.
π@cveNotify
Parse Server is an open-source backend server. In versions >= 9.0.0 and < 9.10.1-alpha.8, and in versions < 8.6.89, LiveQuery evaluates the protectedFields class-level permission against an incompletely resolved caller identity: the subscriber's roles are not resolved, and when a subscription does not supply its own session token the event payload is redacted against an anonymous identity even though the read was authorized against the connected user. As a result, field masks defined for a role, for authenticated users, or for a specific user are not applied, so an authenticated subscriber can receive field values that the REST API correctly withholds and can use a masked field to filter or watch a subscription. Only classes with LiveQuery enabled that define protectedFields under a role:, authenticated, or per-user group are affected; masks under the public (*) group are applied correctly. The issue is fixed in 9.10.1-alpha.8 and 8.6.89. As a workaround, additionally define the affected field masks under the public (*) group, or disable LiveQuery for classes whose class-level permissions rely on role-scoped, authenticated, or per-user protectedFields groups.
π@cveNotify
GitHub
LiveQuery discloses protected fields by resolving an incomplete subscriber identity
### Impact
Parse Server's `protectedFields` class-level permission hides specific fields from groups of callers. LiveQuery evaluated these permissions against an incompletely resolved caller...
Parse Server's `protectedFields` class-level permission hides specific fields from groups of callers. LiveQuery evaluated these permissions against an incompletely resolved caller...
π¨ CVE-2026-100633
SiYuan is a self-hosted personal knowledge management system. In versions 3.8.0 through 3.8.3, the MCP file tool's sensitive-path guard (util.IsForbiddenAbsPath(), invoked from resolvePath()) is applied only to the allowed root of recursive operations and not to each resolved descendant path β an incomplete fix for GHSA-c8r8-95hg-mp34. An authenticated administrator using the in-app Agent or the external MCP server can therefore bypass the protected-workspace-file denylist: file.grep can return matching lines from non-hidden protected descendants (for example conf/conf.json, TLS keys, data/snippets/conf.json, data/templates/, data/.siyuan/publishAccess.json, notebook .siyuan internals, or the kernel log), file.copy can copy protected descendants to an ordinary path where file.read can then retrieve them, and unzip can overwrite protected descendants using ordinary, lexically contained ZIP member names. Because file.grep is globally classified as a safe action, it receives no per-call confirmation, and the confirmation cards for file.copy and unzip show only the allowed root arguments. This issue is fixed in version 3.8.4. Suggested title: SiYuan 3.8.0 through 3.8.3 Sensitive-Path Guard Bypass in Recursive MCP File Operations.
π@cveNotify
SiYuan is a self-hosted personal knowledge management system. In versions 3.8.0 through 3.8.3, the MCP file tool's sensitive-path guard (util.IsForbiddenAbsPath(), invoked from resolvePath()) is applied only to the allowed root of recursive operations and not to each resolved descendant path β an incomplete fix for GHSA-c8r8-95hg-mp34. An authenticated administrator using the in-app Agent or the external MCP server can therefore bypass the protected-workspace-file denylist: file.grep can return matching lines from non-hidden protected descendants (for example conf/conf.json, TLS keys, data/snippets/conf.json, data/templates/, data/.siyuan/publishAccess.json, notebook .siyuan internals, or the kernel log), file.copy can copy protected descendants to an ordinary path where file.read can then retrieve them, and unzip can overwrite protected descendants using ordinary, lexically contained ZIP member names. Because file.grep is globally classified as a safe action, it receives no per-call confirmation, and the confirmation cards for file.copy and unzip show only the allowed root arguments. This issue is fixed in version 3.8.4. Suggested title: SiYuan 3.8.0 through 3.8.3 Sensitive-Path Guard Bypass in Recursive MCP File Operations.
π@cveNotify
GitHub
Incomplete fix for GHSA-c8r8-95hg-mp34: recursive MCP file operations bypass the sensitive-path guard
# Private advisory report
## Proposed title
Incomplete fix for GHSA-c8r8-95hg-mp34: recursive MCP file operations bypass the sensitive-path guard
## Suggested metadata
| Field | Value |...
## Proposed title
Incomplete fix for GHSA-c8r8-95hg-mp34: recursive MCP file operations bypass the sensitive-path guard
## Suggested metadata
| Field | Value |...
π¨ CVE-2026-100635
SiYuan before v3.8.4 contains an authentication bypass vulnerability in the publish service where session cookies are issued without Secure or SameSite attributes over plaintext HTTP connections. An on-path attacker can observe a valid publish-visitor-session-id cookie from a Basic Auth exchange and replay it to access authenticated publish endpoints without knowing the account password.
π@cveNotify
SiYuan before v3.8.4 contains an authentication bypass vulnerability in the publish service where session cookies are issued without Secure or SameSite attributes over plaintext HTTP connections. An on-path attacker can observe a valid publish-visitor-session-id cookie from a Basic Auth exchange and replay it to access authenticated publish endpoints without knowing the account password.
π@cveNotify
GitHub
:art: Improve publish session invalidation after account password cha⦠· siyuan-note/siyuan@79d4786
β¦nges https://github.com/siyuan-note/siyuan/issues/19097
π¨ CVE-2026-100636
SiYuan versions before v3.8.4 contain a path traversal vulnerability in the exportBrowserHTML endpoint that allows authenticated administrators to write arbitrary HTML content to index.html outside the workspace directory. Attackers can supply a folder parameter with directory traversal sequences to escape the export directory and overwrite index.html in any pre-existing kernel-writable location, enabling stored XSS or workspace defacement.
π@cveNotify
SiYuan versions before v3.8.4 contain a path traversal vulnerability in the exportBrowserHTML endpoint that allows authenticated administrators to write arbitrary HTML content to index.html outside the workspace directory. Attackers can supply a folder parameter with directory traversal sequences to escape the export directory and overwrite index.html in any pre-existing kernel-writable location, enabling stored XSS or workspace defacement.
π@cveNotify
GitHub
Admin path traversal in exportBrowserHTML via folder allows out-of-workspace arbitrary-content index.html write
## Summary
`exportBrowserHTML` (`kernel/api/export.go:842-875`) binds the request `folder` field with **no** `..`/containment check, then builds `tmpDir := filepath.Join(util.TempDir, "export...
`exportBrowserHTML` (`kernel/api/export.go:842-875`) binds the request `folder` field with **no** `..`/containment check, then builds `tmpDir := filepath.Join(util.TempDir, "export...
π¨ CVE-2026-100637
SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authenticated administrators to write JSON files outside the workspace. Attackers can supply a sessionID parameter containing directory traversal sequences to overwrite arbitrary JSON files in pre-existing kernel-writable directories outside workspace boundaries.
π@cveNotify
SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authenticated administrators to write JSON files outside the workspace. Attackers can supply a sessionID parameter containing directory traversal sequences to overwrite arbitrary JSON files in pre-existing kernel-writable directories outside workspace boundaries.
π@cveNotify
GitHub
Admin path traversal in checkoutRepo via sessionID allows out-of-workspace JSON file write
## Summary
`checkoutRepo` (`kernel/api/repo.go:241-254`) binds the request `sessionID` field with **no** pattern/containment check, then builds `markerPath := filepath.Join(util.TempDir, "ai&...
`checkoutRepo` (`kernel/api/repo.go:241-254`) binds the request `sessionID` field with **no** pattern/containment check, then builds `markerPath := filepath.Join(util.TempDir, "ai&...
π¨ CVE-2026-100638
SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authenticated administrators to create arbitrary directory trees and write files outside the workspace boundary. Attackers can supply directory traversal sequences in the notebook parameter to escape the workspace data directory and write conf.json files to arbitrary locations accessible by the kernel process.
π@cveNotify
SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authenticated administrators to create arbitrary directory trees and write files outside the workspace boundary. Attackers can supply directory traversal sequences in the notebook parameter to escape the workspace data directory and write conf.json files to arbitrary locations accessible by the kernel process.
π@cveNotify
GitHub
Admin path traversal in setNotebookIcon allows out-of-workspace directory creation and conf.json write
## Summary
`setNotebookIcon` (`kernel/api/notebook.go:74-96`) binds the request `notebook` field into `boxID` **without** the `util.InvalidIDPattern` (`ast.IsNodeIDPattern`) guard that every sibli...
`setNotebookIcon` (`kernel/api/notebook.go:74-96`) binds the request `notebook` field into `boxID` **without** the `util.InvalidIDPattern` (`ast.IsNodeIDPattern`) guard that every sibli...
π¨ CVE-2026-100639
SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button markup (app/src/protyle/gutter/button.ts, assigned via innerHTML in app/src/protyle/gutter/index.ts) from content pasted as plain-text Markdown containing a Kramdown inline attribute list (IAL). Because the shared Lute renderer parses Kramdown IAL from text/plain input, an attacker-supplied Markdown snippet using entity-encoded quotes in data-subtype breaks out of the attribute value when the gutter markup is re-parsed by the browser, injecting additional attributes such as autofocus and onfocus. If a victim pastes the crafted Markdown and the affected gutter control receives focus, the injected handler executes; in the Electron desktop application, where the main BrowserWindow enables Node integration and disables context isolation, this results in JavaScript execution with renderer Node.js privileges (remote code execution). Fixed in v3.8.4.
π@cveNotify
SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button markup (app/src/protyle/gutter/button.ts, assigned via innerHTML in app/src/protyle/gutter/index.ts) from content pasted as plain-text Markdown containing a Kramdown inline attribute list (IAL). Because the shared Lute renderer parses Kramdown IAL from text/plain input, an attacker-supplied Markdown snippet using entity-encoded quotes in data-subtype breaks out of the attribute value when the gutter markup is re-parsed by the browser, injecting additional attributes such as autofocus and onfocus. If a victim pastes the crafted Markdown and the affected gutter control receives focus, the injected handler executes; in the Electron desktop application, where the main BrowserWindow enables Node integration and disables context isolation, this results in JavaScript execution with renderer Node.js privileges (remote code execution). Fixed in v3.8.4.
π@cveNotify
GitHub
Plain-text Kramdown IAL paste causes gutter attribute injection and desktop RCE
# Plain-text Kramdown IAL paste causes gutter attribute injection and desktop RCE
## Summary
SiYuan v3.8.3 decodes attacker-controlled Kramdown IAL from ordinary `text/plain` Markdown and pas...
## Summary
SiYuan v3.8.3 decodes attacker-controlled Kramdown IAL from ordinary `text/plain` Markdown and pas...
π¨ CVE-2026-100640
SiYuan before v3.8.4 contains an authorization omission in the siyuan-get IPC handler that allows remote-kernel renderers to access native clipboard formats by invoking clipboardReadMathML, clipboardReadOffice, and clipboardReadWPS commands with matching plaintext. Attackers controlling remote renderer content can obtain MathML formulas, Office bytes, and WPS bytes from local clipboard during user-mediated paste operations.
π@cveNotify
SiYuan before v3.8.4 contains an authorization omission in the siyuan-get IPC handler that allows remote-kernel renderers to access native clipboard formats by invoking clipboardReadMathML, clipboardReadOffice, and clipboardReadWPS commands with matching plaintext. Attackers controlling remote renderer content can obtain MathML formulas, Office bytes, and WPS bytes from local clipboard during user-mediated paste operations.
π@cveNotify
GitHub
Remote-kernel Electron IPC exposes native clipboard contents to a remote window
# Remote-kernel Electron IPC exposes native clipboard contents to a remote window
## Summary
At the tested revision `8641553a1f07374001902d3ce773285db1292b2d`, a remote-kernel renderer can in...
## Summary
At the tested revision `8641553a1f07374001902d3ce773285db1292b2d`, a remote-kernel renderer can in...
π¨ CVE-2026-100641
SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager list markup. Block content returned by /api/riff/getRiffCards is inserted into a card item template in app/src/card/viewCards.ts and assigned to listElement.innerHTML, so content such as <img src=invalid onerror=...> becomes an executable event-handler attribute. Because the SiYuan desktop (Electron) main window is created with nodeIntegration enabled and contextIsolation disabled, an administrator who opens the card manager on a workspace containing attacker-supplied flashcard content (for example introduced through contribution or import) executes the attacker's script in a privileged renderer, which can lead to arbitrary code execution on the host. The affected endpoint remains behind authentication and administrator-role checks; this is an untrusted-content-to-privileged-renderer issue, not an authorization bypass.
π@cveNotify
SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager list markup. Block content returned by /api/riff/getRiffCards is inserted into a card item template in app/src/card/viewCards.ts and assigned to listElement.innerHTML, so content such as <img src=invalid onerror=...> becomes an executable event-handler attribute. Because the SiYuan desktop (Electron) main window is created with nodeIntegration enabled and contextIsolation disabled, an administrator who opens the card manager on a workspace containing attacker-supplied flashcard content (for example introduced through contribution or import) executes the attacker's script in a privileged renderer, which can lead to arbitrary code execution on the host. The affected endpoint remains behind authentication and administrator-role checks; this is an untrusted-content-to-privileged-renderer issue, not an authorization bypass.
π@cveNotify
GitHub
:bug: Refill flashcard pages after removing cards https://github.com/β¦ Β· siyuan-note/siyuan@1ecb1c0
β¦siyuan-note/siyuan/issues/13988
π¨ CVE-2026-100642
SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-screen pass-through branch that grants administrator access to loopback requests without validating Origin headers. Attackers can craft malicious web pages that force victims to terminate the kernel process, read workspace configuration and proxy settings, and trigger administrative actions via zero-credential cross-origin requests from the victim's browser.
π@cveNotify
SiYuan versions from v2.1.0 before v3.8.4 contain a cross-site request forgery vulnerability in the CheckAuth lock-screen pass-through branch that grants administrator access to loopback requests without validating Origin headers. Attackers can craft malicious web pages that force victims to terminate the kernel process, read workspace configuration and proxy settings, and trigger administrative actions via zero-credential cross-origin requests from the victim's browser.
π@cveNotify
GitHub
Lock-screen pass-through branch of `CheckAuth` skips Origin validation β any web page can force-exit a lock-screen-protected SiYuanβ¦
> **affected**: SiYuan (`siyuan-note/siyuan` kernel HTTP API) `>= v2.1.0` β `CheckAuth` localhost pass-through prefixes (`/api/system/exit`, `/api/system/getNetwork`, `/api/system/getWorkspac...
π¨ CVE-2026-100643
SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing authenticated attackers to inject JavaScript by modifying field descriptions, template sources, select option descriptions, or footer calculation templates. Attackers can execute stored JavaScript when other users open affected database menus, and in the Electron desktop app with nodeIntegration enabled, this leads to command execution with SiYuan process privileges.
π@cveNotify
SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing authenticated attackers to inject JavaScript by modifying field descriptions, template sources, select option descriptions, or footer calculation templates. Attackers can execute stored JavaScript when other users open affected database menus, and in the Electron desktop app with nodeIntegration enabled, this leads to command execution with SiYuan process privileges.
π@cveNotify
GitHub
Incomplete fix for GHSA-gcm3-qcq3-72rv leaves stored XSS in Attribute View textarea editors
### Summary
SiYuan v3.8.3 still inserts four stored Attribute View values into `textarea` bodies without HTML escaping. Opening the affected database menus executes stored JavaScript. In the Ele...
SiYuan v3.8.3 still inserts four stored Attribute View values into `textarea` bodies without HTML escaping. Opening the affected database menus executes stored JavaScript. In the Ele...
π¨ CVE-2026-100644
SiYuan before v3.8.4 contains a SQL injection vulnerability in the graph query endpoint where the dailyNoteSavePath parameter is concatenated into SQL without escaping. Unauthenticated attackers on published sites with auth disabled can inject SQL via UNION SELECT to extract arbitrary database rows from all notebooks.
π@cveNotify
SiYuan before v3.8.4 contains a SQL injection vulnerability in the graph query endpoint where the dailyNoteSavePath parameter is concatenated into SQL without escaping. Unauthenticated attackers on published sites with auth disabled can inject SQL via UNION SELECT to extract arbitrary database rows from all notebooks.
π@cveNotify
GitHub
SQL injection in graph query via unsanitized dailyNoteSavePath
### Summary
SiYuan's graph endpoints concatenate a notebook's stored `dailyNoteSavePath` into a SQL string literal without escaping. A quote closes the literal and appends attacker-chosen ...
SiYuan's graph endpoints concatenate a notebook's stored `dailyNoteSavePath` into a SQL string literal without escaping. A quote closes the literal and appends attacker-chosen ...
π¨ CVE-2026-100645
SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery and kanban database renderers where field descriptions are not escaped in aria-label attributes. In the Electron desktop app with nodeIntegration enabled, attackers can inject JavaScript that calls Node.js child_process APIs to execute arbitrary commands with user privileges.
π@cveNotify
SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery and kanban database renderers where field descriptions are not escaped in aria-label attributes. In the Electron desktop app with nodeIntegration enabled, attackers can inject JavaScript that calls Node.js child_process APIs to execute arbitrary commands with user privileges.
π@cveNotify
GitHub
Stored XSS in leads to RCE in the Electron desktop app
### Summary
SiYuan v3.8.3 has a stored XSS vulnerability in the gallery and kanban database renderers. In the Electron desktop app, the XSS can use Node.js APIs to execute commands on the user&#...
SiYuan v3.8.3 has a stored XSS vulnerability in the gallery and kanban database renderers. In the Electron desktop app, the XSS can use Node.js APIs to execute commands on the user&#...
π¨ CVE-2026-100646
SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3, the kernel's authentication guards (CheckAuth in kernel/model/session.go and IsSessionOriginAllowed in kernel/util/net.go) fail open when the HTTP Origin header is absent, on the incorrect assumption that any browser-initiated cross-site request carries an Origin. Because browsers omit Origin on cross-site top-level GET navigations and no-cors GET subresource loads β and the session cookie is SameSite=Lax β a single cross-site GET issued from any attacker-controlled web page is granted RoleAdministrator, both on default installations with no access-authorization code and on password-protected instances with a live session. Combined with content-type sniffing on the /api/network/proxy endpoint, which allows attacker-controlled HTML to be served under SiYuan's own origin, this permits an unauthenticated remote attacker to execute arbitrary script in the SiYuan origin (http://127.0.0.1:6806), invoke administrator APIs, and exfiltrate the persistent kernel API token. This issue is fixed in version 3.8.4.
π@cveNotify
SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3, the kernel's authentication guards (CheckAuth in kernel/model/session.go and IsSessionOriginAllowed in kernel/util/net.go) fail open when the HTTP Origin header is absent, on the incorrect assumption that any browser-initiated cross-site request carries an Origin. Because browsers omit Origin on cross-site top-level GET navigations and no-cors GET subresource loads β and the session cookie is SameSite=Lax β a single cross-site GET issued from any attacker-controlled web page is granted RoleAdministrator, both on default installations with no access-authorization code and on password-protected instances with a live session. Combined with content-type sniffing on the /api/network/proxy endpoint, which allows attacker-controlled HTML to be served under SiYuan's own origin, this permits an unauthenticated remote attacker to execute arbitrary script in the SiYuan origin (http://127.0.0.1:6806), invoke administrator APIs, and exfiltrate the persistent kernel API token. This issue is fixed in version 3.8.4.
π@cveNotify
GitHub
Missing-Origin fail-open in `CheckAuth` / `IsSessionOriginAllowed`, composed with content-type sniffing on `/api/network/proxy`:β¦
## Summary
Two guards in the kernel treat an **absent** `Origin` header as trusted, and a third code
path lets an attacker serve arbitrary HTML **under SiYuan's own origin**. Composed, a si...
Two guards in the kernel treat an **absent** `Origin` header as trusted, and a third code
path lets an attacker serve arbitrary HTML **under SiYuan's own origin**. Composed, a si...
π¨ CVE-2026-100647
vLLM versions before 0.29.0 contain a denial-of-service vulnerability in the cache_salt parameter accepted on OpenAI-compatible and Anthropic API endpoints, which lacks maximum length validation and is processed on the single EngineCore scheduler thread. Unauthenticated attackers can send HTTP requests with multi-hundred-megabyte salt values that trigger expensive pickle serialization and SHA-256 hashing, stalling the scheduler thread and denying service to all concurrent requests.
π@cveNotify
vLLM versions before 0.29.0 contain a denial-of-service vulnerability in the cache_salt parameter accepted on OpenAI-compatible and Anthropic API endpoints, which lacks maximum length validation and is processed on the single EngineCore scheduler thread. Unauthenticated attackers can send HTTP requests with multi-hundred-megabyte salt values that trigger expensive pickle serialization and SHA-256 hashing, stalling the scheduler thread and denying service to all concurrent requests.
π@cveNotify
GitHub
vLLM DoS via unbounded `cache_salt` length: multi-hundred-MB salt stalls the single EngineCore scheduler thread (CPU exhaustion)
### Summary
An unauthenticated remote attacker can exhaust the CPU of the single EngineCore scheduler thread and stall every request on the server by sending HTTP requests with an oversized `cac...
An unauthenticated remote attacker can exhaust the CPU of the single EngineCore scheduler thread and stall every request on the server by sending HTTP requests with an oversized `cac...
π¨ CVE-2026-100648
vllm before 0.29.0 fails to enforce VLLM_MAX_AUDIO_CLIP_FILESIZE_MB limit in multimodal chat audio decoding, allowing unauthenticated clients to bypass file size restrictions. Attackers can submit oversized audio files through chat endpoints to consume excessive memory and CPU resources during decoding.
π@cveNotify
vllm before 0.29.0 fails to enforce VLLM_MAX_AUDIO_CLIP_FILESIZE_MB limit in multimodal chat audio decoding, allowing unauthenticated clients to bypass file size restrictions. Attackers can submit oversized audio files through chat endpoints to consume excessive memory and CPU resources during decoding.
π@cveNotify
GitHub
Uncontrolled resource consumption: multimodal chat audio decoding ignores `VLLM_MAX_AUDIO_CLIP_FILESIZE_MB`
## Summary
`MediaConnector.fetch_audio` passes multimodal chat audio bytes directly to `AudioMediaIO.load_bytes` without checking `VLLM_MAX_AUDIO_CLIP_FILESIZE_MB` (`vllm/multimodal/media/connec...
`MediaConnector.fetch_audio` passes multimodal chat audio bytes directly to `AudioMediaIO.load_bytes` without checking `VLLM_MAX_AUDIO_CLIP_FILESIZE_MB` (`vllm/multimodal/media/connec...
π¨ CVE-2026-100649
vLLM before 0.29.0 contains a resource-limit bypass vulnerability in PyNvVideoCodec decoder allocation where sampler subclass shadowing allows independent counter increments. Unauthenticated attackers can select different sampler subclasses in video requests to exceed configured decoder limits and exhaust unaccounted GPU memory.
π@cveNotify
vLLM before 0.29.0 contains a resource-limit bypass vulnerability in PyNvVideoCodec decoder allocation where sampler subclass shadowing allows independent counter increments. Unauthenticated attackers can select different sampler subclasses in video requests to exceed configured decoder limits and exhaust unaccounted GPU memory.
π@cveNotify
GitHub
Sampler Subclass Counter Shadowing Bypasses PyNvVideoCodec Decoder Limits and GPU Memory Accounting
### Summary
In vLLM v0.27.0, unauthenticated video requests can select different stock sampler subclasses while using the statically configured PyNvVideoCodec backend. Because `_active_decoder_s...
In vLLM v0.27.0, unauthenticated video requests can select different stock sampler subclasses while using the statically configured PyNvVideoCodec backend. Because `_active_decoder_s...
π¨ CVE-2026-100650
vLLM through 0.29.0 fetches and fully materializes remote or inline media before enforcing its documented media controls (the VLLM_MAX_AUDIO_CLIP_FILESIZE_MB compressed-audio size cap, default 25 MB, and the per-modality --limit-mm-per-prompt item limits). Across four ingress paths β the shared media-acquisition layer (HTTPConnection.get_bytes()/async_get_bytes()), the chat completions audio_url/base64 path, the batch speech runner, and the Rust frontend POST /tokenize route β the server reads the entire HTTP response body, base64-decodes the inline payload, or spawns one fetch/decode task per media part, and only then applies the limit (or, on some paths, never applies it). A remote attacker can therefore cause the API server or batch-runner process to allocate memory and consume outbound bandwidth proportional to an attacker-chosen body size or media item count before the request is rejected, resulting in pre-inference memory and bandwidth exhaustion (denial of service). The chat and batch surfaces require an API key when one is configured; the Rust frontend /tokenize route is unauthenticated by design. There is no code execution or data disclosure impact.
π@cveNotify
vLLM through 0.29.0 fetches and fully materializes remote or inline media before enforcing its documented media controls (the VLLM_MAX_AUDIO_CLIP_FILESIZE_MB compressed-audio size cap, default 25 MB, and the per-modality --limit-mm-per-prompt item limits). Across four ingress paths β the shared media-acquisition layer (HTTPConnection.get_bytes()/async_get_bytes()), the chat completions audio_url/base64 path, the batch speech runner, and the Rust frontend POST /tokenize route β the server reads the entire HTTP response body, base64-decodes the inline payload, or spawns one fetch/decode task per media part, and only then applies the limit (or, on some paths, never applies it). A remote attacker can therefore cause the API server or batch-runner process to allocate memory and consume outbound bandwidth proportional to an attacker-chosen body size or media item count before the request is rejected, resulting in pre-inference memory and bandwidth exhaustion (denial of service). The chat and batch surfaces require an API key when one is configured; the Rust frontend /tokenize route is unauthenticated by design. There is no code execution or data disclosure impact.
π@cveNotify
GitHub
[Bugfix] Guard mixed-dtype allreduce RMSNorm quant fusions (#48330) Β· vllm-project/vllm@752a3a5
Signed-off-by: hcenteno <hugo.centeno@estudiantat.upc.edu>
(cherry picked from commit 5f8e73cb8b8d41f7a2a5168cddf5b772888fa991)
(cherry picked from commit 5f8e73cb8b8d41f7a2a5168cddf5b772888fa991)