
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34449 is a Critical-severity Cross-Origin Remote Code Execution (RCE) vulnerability in SiYuan, a personal knowledge management system built on Electron. By exploiting SiYuan's permissive CORS policy (Access-Control-Allow-Origin: * combined with Access-Control-Allow-Private-Network: true), a malicious website can inject a JavaScript snippet via the /api/snippet/setSnippet API endpoint; the snippet subsequently executes in Electron's Node.js context with full OS-level access when the user next opens SiYuan's UI. All SiYuan desktop versions up to and including v3.6.1 are affected; the issue was patched in v3.6.2, released March 31, 2026. It carries a CVSS v3.1 base score of 9.6 (Critical) (Github Advisory, SiYuan Advisory).
The root cause is classified as CWE-942 (Permissive Cross-domain Policy with Untrusted Domains). The vulnerable CORS middleware in kernel/server/serve.go (lines 960–963) unconditionally sets Access-Control-Allow-Origin: *, Access-Control-Allow-Credentials: true, and Access-Control-Allow-Private-Network: true, explicitly opting into Chrome's Private Network Access specification and permitting any external website to make authenticated cross-origin requests to the SiYuan API at 127.0.0.1:6806. The authentication middleware in kernel/model/session.go performs an Origin header check, but this is bypassed because the browser automatically includes the session cookie (scoped to 127.0.0.1) with the cross-origin request, and the server validates the cookie before reaching the Origin check. The snippet injection endpoint (kernel/api/snippet.go, lines 93–128) then saves the attacker-supplied JavaScript, which executes in Electron's renderer process with Node.js integration enabled, achieving arbitrary OS command execution (SiYuan Advisory).
Successful exploitation grants an attacker full OS-level code execution with the privileges of the SiYuan user process, enabling arbitrary command execution, file system access, and persistence across restarts (since the injected snippet is saved to disk and re-executed every time SiYuan loads). Additionally, before the RCE payload triggers, the attacker can exfiltrate all notes, workspace data, API tokens, and configuration via the /api/system/getConf endpoint — all in a single page load with no additional user interaction. The scope change (from browser sandbox to host OS) and the combination of high confidentiality, integrity, and availability impact make this a particularly severe vulnerability for all SiYuan desktop users (SiYuan Advisory, Github Advisory).
A complete, actionable proof-of-concept exploit — including a malicious HTML/JavaScript payload targeting http://127.0.0.1:6806/api/snippet/setSnippet and verification steps using curl with session cookies — is publicly available in the GitHub Security Advisory (SiYuan Advisory). The exploit was tested and confirmed on SiYuan v3.6.1 (Docker). The only precondition is that the victim visits a malicious webpage while SiYuan is running and has an active session cookie in the same browser. The EPSS score is approximately 0.138% (per Feedly) to 0.236% (per GitHub Advisory), indicating a relatively low but non-negligible probability of exploitation in the wild. No in-the-wild exploitation or CISA KEV catalog listing has been reported as of the time of this report (Github Advisory).
http://127.0.0.1:6806. This can be inferred from public user profiles, forums, or by broadly targeting SiYuan's user base.https://evil-attacker.com) containing a JavaScript payload.OPTIONS) request to http://127.0.0.1:6806. SiYuan responds with permissive headers (Access-Control-Allow-Origin: *, Access-Control-Allow-Private-Network: true), allowing the browser to proceed.POST request to http://127.0.0.1:6806/api/snippet/setSnippet with credentials: 'include', automatically attaching the victim's session cookie. The payload body injects a JS snippet with content such as require("child_process").exec("id > /tmp/siyuan-rce-proof").fetch to /api/system/getConf retrieves the API token and full configuration, which is then sent to the attacker's server via a POST to https://evil-attacker.com/collect.curl -X POST http://127.0.0.1:6806/api/snippet/getSnippet -H "Content-Type: application/json" -b <cookie> -d '{"type":"all","enabled":2}' (SiYuan Advisory).OPTIONS) requests from the browser to http://127.0.0.1:6806 originating from external domains; outbound POST requests from the SiYuan host to unknown external servers (e.g., attacker's data collection endpoint).POST /api/snippet/setSnippet requests with an Origin header from an external domain (e.g., Origin: https://evil-attacker.com); POST /api/system/getConf requests from unexpected origins./tmp/siyuan-rce-proof or other attacker-created artifacts on the host filesystem.sh, bash, cmd.exe, curl, wget, python) executing commands not initiated by the user; unexpected network connections from the Electron process to external IPs (SiYuan Advisory).The primary remediation is to upgrade SiYuan to version 3.6.2 or later, which patches the permissive CORS policy and the snippet injection vulnerability (SiYuan Release, Github Advisory). As a temporary workaround for users unable to upgrade immediately, restrict browser access to untrusted or unknown websites while SiYuan is running, or isolate SiYuan to a network environment where it cannot be reached from a browser navigating external sites. Users should also audit existing JS snippets in SiYuan for any unexpected or unfamiliar entries that may indicate prior exploitation.
The vulnerability received coverage from threat intelligence outlets including The Hacker Wire, which published a dedicated write-up on the CORS-based RCE (The Hacker Wire), and Yazoul.net published an advisory (Yazoul Advisory). The vulnerability was also discussed on Mastodon and Bluesky security communities shortly after disclosure. A Medium post by Loginsoft included CVE-2026-34449 in a roundup of active exploits from late March to early April 2026. The SiYuan maintainer (88250) addressed the issue promptly, bundling the fix with several other security patches in the v3.6.2 release.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."