CVE-2026-74867

LOW CVSS 4.0: 2.3 EPSS 0.10%
Updated Aug 26, 2026
SiYuan
Parameter Value
CVSS 2.3 (LOW)
Affected Versions before 3.7.4
Type CWE-352 (Cross-Site Request Forgery (CSRF))
Vendor SiYuan
Public PoC No

SiYuan versions before 3.7.4 contain a cross-site request forgery vulnerability in the session-cookie authentication branch of CheckAuth() that lacks Origin/Referer validation and sets no explicit SameSite attribute on session cookies. Attackers can craft malicious web pages that perform unauthorized actions on behalf of authenticated users by submitting requests with valid session cookies, relying on browser default SameSite policies rather than server-enforced protections.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
None
No privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v4.0