<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T07:04:59.086075+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-330238</id>
    <title>EUVD-2026-330238</title>
    <updated>2026-10-06T07:04:59.132855+00:00</updated>
    <content>EUVD-2026-330238</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-330238"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54069</id>
    <title>fkie_cve-2026-54069</title>
    <updated>2026-10-06T07:04:59.132892+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan Note's kernel HTTP server unconditionally trusts all chrome-extension:// origins, granting RoleAdministrator access to every installed browser extension without any authentication. Combined with the default empty AccessAuthCode on desktop installs, any Chrome/Chromium extension -- including a compromised legitimate extension via supply chain attack -- can make fully authenticated admin API calls to the SiYuan kernel at 127.0.0.1:6806, enabling data exfiltration, stored XSS injection, and configuration tampering. This vulnerability is fixed in 3.7.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54069"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hvr9-72v2-fff3</id>
    <title>GHSA-hvr9-72v2-fff3 — SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist</title>
    <updated>2026-10-06T07:04:59.132926+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/siyuan-note/siyuan/kernel</p>
<p>## Summary</p>
<p>SiYuan Note's kernel HTTP server unconditionally trusts all `chrome-extension://` origins, granting `RoleAdministrator` access to every installed browser extension without any authentication. Combined with the default empty `AccessAuthCode` on desktop installs, any Chrome/Chromium extension -- including a compromised legitimate extension via supply chain attack -- can make fully authenticated admin API calls to the SiYuan kernel at `127.0.0.1:6806`, enabling data exfiltration, stored XSS injection, and configuration tampering.</p>
<p>## Affected Versions</p>
<p>SiYuan &lt;= v3.6.5 (commit `96dfe0bea474`). The chrome-extension allowlist remains unfixed as of the latest commit on the fix branch (`d7b77d945e0d`).</p>
<p>## Vulnerability Details</p>
<p>### Blanket chrome-extension:// Origin Trust (CWE-346)</p>
<p>In `kernel/model/session.go:277`, the `CheckAuth` middleware exempts all `chrome-extension://` origins from authentication:</p>
<p>```go
if strings.HasPrefix(origin, "chrome-extension://") {
    // skip auth
}
```</p>
<p>At `session.go:284`, the request is assigned `RoleAdministrator`:</p>
<p>```go
c.Set("role", model.RoleAdministrator)
```</p>
<p>The `AccessAuthCode` field defaults to an empty string for desktop installs (`ContainerStd`). When empty, no token validation occurs. This means **any** Chrome/Chromium extension can make fully authenticated admin API calls to the SiYuan kernel.</p>
<p>The origin check trusts the entire `chrome-extension://` scheme rather than validating a specific extension ID, so every insta…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hvr9-72v2-fff3"/>
  </entry>
</feed>
