PatchSiren cyber security CVE debrief
CVE-2026-100634 siyuan-note CVE debrief
SiYuan before v3.8.4 has a missing authorization vulnerability via siyuan-send-windows, allowing a remote workspace to repeatedly lock unrelated local workspace windows, causing a limited denial of service. This issue arises from the 'siyuan-send-windows' IPC handler in the Electron main process, which fails to validate the sender or restrict recipients. Consequently, a renderer connected to an attacker-controlled remote kernel can send {cmd: 'lockscreenByMode'} and have it delivered across the workspace boundary, affecting windows in other workspaces. The vulnerability impacts SiYuan deployments, emphasizing the need for defenders to assess exposure and prioritize upgrading to a 3
- Vendor
- siyuan-note
- Product
- siyuan
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-26
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-09-26
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for SiYuan deployments should assess exposure and prioritize upgrading to version 3.8.4 or later to prevent exploitation. Additionally, security teams should review Electron process configurations, monitor for suspicious IPC handler activity, and consider compensating controls for exposed systems. Operational impact may include disruptions to workspace productivity and user experience due to repeated locking of unrelated local windows
Why it matters
CVE-2026-100634 is a missing authorization vulnerability in SiYuan before v3.8.4, allowing a remote workspace to repeatedly lock unrelated local workspace windows, causing a limited denial of service. Defenders should prioritize verifying and upgrading to version 3.8.4 or later to prevent exploitation.
- Denial of service through repeated locking of unrelated local workspace windows
- Potential disruption to workspace productivity and user experience
Technical summary
The 'siyuan-send-windows' IPC handler in SiYuan before v3.8.4 does not validate the sender or restrict recipients, allowing a remote workspace to send {cmd: 'lockscreenByMode'} and lock unrelated local workspace windows. This is possible because the handler ignores event.sender and forwards payloads to all BrowserWindows, including those in different workspaces. The issue enables a limited denial-of-service attack, where an attacker can repeatedly lock windows across workspaces, disrupting user productivity. The vulnerability is localized to the IPC handler in the Electron main process.
Defensive priority
Defenders should prioritize verifying and upgrading to version 3.8.4 or later to prevent exploitation.
Recommended defensive actions
- Verify and upgrade SiYuan to version 3.8.4 or later
- Restrict access to the 'siyuan-send-windows' IPC handler
- Monitor for suspicious activity in Electron main process
- Implement additional logging for IPC handler interactions
- Conduct regular security audits of Electron process configurations
- Review and enhance workspace isolation settings
- Track and manage software updates for SiYuan
Evidence notes
The vulnerability exists in the 'siyuan-send-windows' IPC handler of the Electron main process, which ignores event.sender and forwards any received payload to every BrowserWindow. A renderer connected to an attacker-controlled remote kernel can send {cmd: 'lockscreenByMode'} and have it delivered across the workspace boundary. The handler's lack of sender validation and recipient restriction enables this unauthorized action.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-100634 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-100634
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-100634 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100634
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
SiYuan before v3.8.4 Missing Authorization via siyuan-send-windows
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/100xxx/CVE-2026-100634.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-wxp7-xpq8-8xpm
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/siyuan-note/siyuan/commit/8641553a1f07374001902d3ce773285db1292b2d
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/siyuan-before-3.8.4-missing-authorization-via-siyuan-send-windows
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.