Ten SiYuan CVEs Landed in One Batch — and the Release Notes Called Them “Some security vulnerabilities”
On 26 September 2026, VulnCheck published ten consecutive CVEs — CVE-2026-100633 through CVE-2026-100642 — against SiYuan, the self-hosted knowledge workspace that markets itself as a place “where humans and AI agents work together” and carries roughly 46,500 GitHub stars. Every one of them is fixed in v3.8.4, which shipped on 17 September. Nine days separated the fix from the public record.
The v3.8.4 release notes run to about 15,000 characters of changelog. The security content is one bullet, linking an issue titled “Some security vulnerabilities.” No CVE, no GHSA, no severity, no affected-version statement. An administrator reading that changelog had no way to know they were looking at a ten-CVE batch that includes privileged renderer code execution.
The MCP finding is an incomplete fix, and that is the interesting part
CVE-2026-100633 (CVSS 4.0 8.5, CWE-863 Incorrect Authorization) is explicitly filed as an incomplete fix for the earlier GHSA-c8r8-95hg-mp34. The original remediation centralized SiYuan’s protected-file denylist in util.IsForbiddenAbsPath() and called it from the MCP file tool’s resolvePath(). A direct MCP read of conf/conf.json, TLS keys, data/snippets/conf.json, data/templates/, or data/.siyuan/publishAccess.json is refused. That part works.
The gap is that three recursive operations validate only the root the caller named, then touch descendants without re-checking each resolved path. Per the advisory: file.grep rooted at an allowed directory returns matching lines from protected non-hidden descendants; file.copy clones a protected file to an ordinary path where a plain file.read then succeeds; and unzip overwrites protected files using ordinary, lexically-contained archive member names — no .., no absolute path, no symlink race required.
This is a clean statement of a bug class we keep seeing in tool-calling surfaces: authorizing a container is not authorizing its contents. The guard was correct for the single final path it was written to check. It became wrong the moment callers passed it a recursion root instead. The same shape appeared in DBHub’s read-only mode that was never wired to the database layer — a control that looks present in the code path a reviewer reads, and is absent in the path the data actually takes.
Why the in-app Agent path is worse than the external MCP path
The advisory draws a distinction worth copying into your own threat models. SiYuan exposes these tools two ways. The external MCP server sits behind authentication and an administrator-role check, and the advisory is candid that an administrator already has broad raw-file HTTP APIs — so it explicitly declines to claim privilege escalation there.
The in-app Agent path is different. SiYuan classifies grep globally as a safe action, so file.grep receives neither a per-call confirmation prompt nor a repository snapshot under the default policy. file.copy and unzip do get a confirmation card — but that card shows only the root arguments the caller supplied, not the protected descendants that will actually be opened or created. The human approves “copy the conf directory” and cannot see that this means “and hand conf.json, including the workspace access credential, API token and cookie signing key, to the model.”
That is the real lesson. A confirmation dialog that renders the requested scope rather than the resolved scope is a consent interface that cannot give informed consent. Recursive tools need their confirmation UI fed from the expansion, not the argument.
Two XSS bugs reach code execution because of an Electron setting
CVE-2026-100639 and CVE-2026-100641 both score 8.6, and both are ordinary missing-escape bugs that become host code execution for one structural reason the advisories state plainly: the SiYuan desktop main window is created with nodeIntegration enabled and contextIsolation disabled.
- CVE-2026-100639 — pasted plain-text Markdown containing a Kramdown inline attribute list is parsed by the shared Lute renderer, and the
data-subtypeattribute is not HTML-escaped when gutter-button markup is built viainnerHTML. Entity-encoded quotes break out of the attribute, injectingautofocusandonfocus. The victim pastes; the control takes focus; the handler runs. - CVE-2026-100641 — stored flashcard block content from
/api/riff/getRiffCardsis interpolated into the card-manager template and assigned toinnerHTML. Content introduced by contribution or import —<img src=invalid onerror=…>— executes when an administrator opens the card manager.
Neither needs a novel primitive. They need untrusted content to reach a renderer that was handed Node.js. For a product whose entire premise is importing other people’s notes and letting agents write into the workspace, “untrusted content reaches the renderer” is not an edge case, it is the feature.
The rest of the batch
- CVE-2026-100635 (8.2) — the publish service issues session cookies without
SecureorSameSiteover plaintext HTTP. An on-path attacker observes apublish-visitor-session-idfrom a Basic Auth exchange and replays it. Authentication bypass without ever learning the password. - CVE-2026-100636, 100637, 100638 (8.3 each) — three separate admin path traversals, in
exportBrowserHTML(arbitrary-contentindex.htmlwrite outside the workspace),checkoutRepoviasessionID(arbitrary JSON overwrite), andsetNotebookIcon(arbitrary directory creation plusconf.jsonwrite). - CVE-2026-100640 (8.6) — the
siyuan-getIPC handler omits an authorization check, letting a renderer connected to a remote kernel read native clipboard formats (MathML, Office, WPS bytes) during user-mediated paste. - CVE-2026-100642 (7.2, affecting v2.1.0 onward — the longest-lived bug in the set) — the
CheckAuthlock-screen pass-through branch grants administrator access to loopback requests without validatingOrigin. A malicious web page can terminate the kernel and read workspace configuration and proxy settings with zero credentials. - CVE-2026-100634 (5.3) — the
siyuan-send-windowsIPC handler ignoresevent.senderand broadcasts to every window, including other workspaces. A remote kernel can repeatedly lock unrelated local workspaces. Limited DoS; no confidentiality or integrity impact observed.
Three of these — 100634, 100640 and the remote-kernel angle generally — share a root cause with the traversal set: the Electron IPC and loopback surfaces were built assuming the renderer is trustworthy. Once “connect to a remote kernel” became a product feature, that assumption stopped holding, and no one re-audited the handlers that depended on it.
This batch is part of a much larger September
The ten CVEs are not the whole picture. The siyuan-note/siyuan repository published 28 security advisories in September 2026 alone — 9 critical, 11 high, 8 medium, by our count against the GitHub advisories API on 27 September. Most carry no CVE ID. They include several more stored-XSS-to-Electron-RCE chains, multiple publish-reader authorization bypasses leaking metadata about password-protected documents, a kernel plugin handler returning arbitrary file content with no path validation, and an OOM kill from a single unauthenticated-reader request to a dynamic-icon endpoint.
We covered this project in July over CVE-2026-66012, where a Reader token reached 31 MCP tools. The pattern since then is not one bad release — it is a mature, popular application that bolted an agent and an MCP server onto an Electron app with permissive renderer settings, and is now paying down the resulting authorization debt in public, at volume. That is arguably the healthier outcome; a maintainer shipping 28 advisories in a month is a maintainer who is actually triaging. But it makes the sparse release-notes disclosure worse, not better, because the fix cadence only helps operators who know to upgrade.
What to do
- Upgrade to v3.8.4 or later immediately. All ten CVEs are fixed there. Every one of the ten lists v3.8.4 as the first unaffected version; 100642 reaches back to v2.1.0, so “we’re on an old stable build” is not a mitigation.
- Treat the publish service as HTTPS-only. CVE-2026-100635 is only exploitable over plaintext. If your publish endpoint is reachable over HTTP on any network segment you do not control, that is the finding to close first.
- Rotate workspace secrets if the MCP or Agent file tools were ever exposed. The confirmed impact of 100633 includes recovery of
conf/conf.json, which may hold the access credential, API token and cookie signing key. Upgrading does not un-disclose them. - Do not connect the desktop client to remote kernels you do not control. Four bugs in this set (100634, 100640, plus the IPC surface generally) are reachable specifically from remote-kernel renderer content.
- Audit your own recursive tools for descendant authorization. If you ship an agent file capability, the question is not “does the guard run” but “does it run on every resolved path, or only the one the caller named.” Add a regression test for the allowed-parent case specifically.
- Feed confirmation prompts from resolved scope. Any tool that expands a root into a set should show the human the set, or at least its size and whether it intersects protected paths.
Sources:
- CVE Record CVE-2026-100633 — SiYuan 3.8.0 through 3.8.3 path traversal via recursive MCP file operations (assigner VulnCheck; published 26 September 2026; CVSS 4.0 8.5; CWE-863)
- GHSA-9g6v-r3xf-673q — Incomplete fix for GHSA-c8r8-95hg-mp34: recursive MCP file operations bypass the sensitive-path guard (published 11 September 2026; patched v3.8.4)
- CVE Record CVE-2026-100639 — Kramdown IAL gutter attribute injection to Electron renderer code execution (CVSS 4.0 8.6)
- CVE Record CVE-2026-100641 — Stored XSS via unescaped flashcard content in the card manager (CVSS 4.0 8.6)
- CVE Record CVE-2026-100635 — Plaintext publish session cookie enables authentication bypass (CVSS 4.0 8.2)
- CVE Record CVE-2026-100642 — CheckAuth lock-screen CSRF, affecting v2.1.0 before v3.8.4 (CVSS 4.0 7.2)
- siyuan-note/siyuan — v3.8.4 release, published 17 September 2026 (remediation floor; security content listed as a single “Some security vulnerabilities” bullet)
- siyuan-note/siyuan — repository security advisories (28 advisories published in September 2026: 9 critical, 11 high, 8 medium, counted 27 September 2026)