PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-100634 siyuan-note CVE debrief

SiYuan before v3.8.4 has a missing authorization vulnerability via siyuan-send-windows, allowing a remote workspace to repeatedly lock unrelated local workspace windows, causing a limited denial of service. This issue arises from the 'siyuan-send-windows' IPC handler in the Electron main process, which fails to validate the sender or restrict recipients. Consequently, a renderer connected to an attacker-controlled remote kernel can send {cmd: 'lockscreenByMode'} and have it delivered across the workspace boundary, affecting windows in other workspaces. The vulnerability impacts SiYuan deployments, emphasizing the need for defenders to assess exposure and prioritize upgrading to a 3

Vendor
siyuan-note
Product
siyuan
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-26
Original CVE updated
2026-10-08
Advisory published
2026-09-26
Advisory updated
2026-10-08

Who should care

Defenders responsible for SiYuan deployments should assess exposure and prioritize upgrading to version 3.8.4 or later to prevent exploitation. Additionally, security teams should review Electron process configurations, monitor for suspicious IPC handler activity, and consider compensating controls for exposed systems. Operational impact may include disruptions to workspace productivity and user experience due to repeated locking of unrelated local windows

Why it matters

CVE-2026-100634 is a missing authorization vulnerability in SiYuan before v3.8.4, allowing a remote workspace to repeatedly lock unrelated local workspace windows, causing a limited denial of service. Defenders should prioritize verifying and upgrading to version 3.8.4 or later to prevent exploitation.

  • Denial of service through repeated locking of unrelated local workspace windows
  • Potential disruption to workspace productivity and user experience

Technical summary

The 'siyuan-send-windows' IPC handler in SiYuan before v3.8.4 does not validate the sender or restrict recipients, allowing a remote workspace to send {cmd: 'lockscreenByMode'} and lock unrelated local workspace windows. This is possible because the handler ignores event.sender and forwards payloads to all BrowserWindows, including those in different workspaces. The issue enables a limited denial-of-service attack, where an attacker can repeatedly lock windows across workspaces, disrupting user productivity. The vulnerability is localized to the IPC handler in the Electron main process.

Defensive priority

Defenders should prioritize verifying and upgrading to version 3.8.4 or later to prevent exploitation.

Recommended defensive actions

  • Verify and upgrade SiYuan to version 3.8.4 or later
  • Restrict access to the 'siyuan-send-windows' IPC handler
  • Monitor for suspicious activity in Electron main process
  • Implement additional logging for IPC handler interactions
  • Conduct regular security audits of Electron process configurations
  • Review and enhance workspace isolation settings
  • Track and manage software updates for SiYuan

Evidence notes

The vulnerability exists in the 'siyuan-send-windows' IPC handler of the Electron main process, which ignores event.sender and forwards any received payload to every BrowserWindow. A renderer connected to an attacker-controlled remote kernel can send {cmd: 'lockscreenByMode'} and have it delivered across the workspace boundary. The handler's lack of sender validation and recipient restriction enables this unauthorized action.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-100634 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-100634

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-100634 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100634

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • SiYuan before v3.8.4 Missing Authorization via siyuan-send-windows

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/100xxx/CVE-2026-100634.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-wxp7-xpq8-8xpm

    Supplemental source - vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/siyuan-note/siyuan/commit/8641553a1f07374001902d3ce773285db1292b2d

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/siyuan-before-3.8.4-missing-authorization-via-siyuan-send-windows

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.