<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 05:43:12 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-278488</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-278488</link>
      <description>EUVD-2026-278488</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-278488</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34449</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34449</link>
      <description>&lt;p&gt;SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting the permissive CORS policy (Access-Control-Allow-Origin: * + Access-Control-Allow-Private-Network: true) to inject a JavaScript snippet via the API. The injected snippet executes in Electron&amp;#39;s Node.js context with full OS access the next time the user opens SiYuan&amp;#39;s UI. No user interaction is required beyond visiting the malicious website while SiYuan is running. This issue has been patched in version 3.6.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting the permissive CORS policy (Access-Control-Allow-Origin: * + Access-Control-Allow-Private-Network: true) to inject a JavaScript snippet via the API. The injected snippet executes in Electron&amp;#39;s Node.js context with full OS access the next time the user opens SiYuan&amp;#39;s UI. No user interaction is required beyond visiting the malicious website while SiYuan is running. This issue has been patched in version 3.6.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34449</guid>
    </item>
    <item>
      <title>GHSA-68p4-j234-43mv — SiYuan is Vulnerable to Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet Injection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-68p4-j234-43mv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting the permissive CORS policy (`Access-Control-Allow-Origin: *` + `Access-Control-Allow-Private-Network: true`) to inject a JavaScript snippet via the API. The injected snippet executes in Electron&amp;#39;s Node.js context with full OS access the next time the user opens SiYuan&amp;#39;s UI. No user interaction is required beyond visiting the malicious website while SiYuan is running.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Vulnerable files:**
- `kernel/server/serve.go`, lines 960-963 — CORS middleware
- `kernel/api/snippet.go`, lines 93-128 — snippet injection endpoint&lt;/p&gt;
&lt;p&gt;**Root cause:** The CORS middleware unconditionally sets:
```
Access-Control-Allow-Origin: *
Access-Control-Allow-Credentials: true
Access-Control-Allow-Private-Network: true
```&lt;/p&gt;
&lt;p&gt;The `Access-Control-Allow-Private-Network: true` header explicitly opts into Chrome&amp;#39;s Private Network Access specification, telling the browser that external websites are permitted to access this localhost service. Combined with `Access-Control-Allow-Origin: *`, any website on the internet can make authenticated cross-origin requests to the SiYuan API at `127.0.0.1:6806`.&lt;/p&gt;
&lt;p&gt;The auth middleware at `kernel/model/session.go:251-280` checks the `Origin` header, but this check is bypassed because the browser sends the session cookie (set on `127.0.0.1`) along with the cross-origin request, and the server validates the cookie before reaching the Origin check for un…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting the permissive CORS policy (`Access-Control-Allow-Origin: *` + `Access-Control-Allow-Private-Network: true`) to inject a JavaScript snippet via the API. The injected snippet executes in Electron&amp;#39;s Node.js context with full OS access the next time the user opens SiYuan&amp;#39;s UI. No user interaction is required beyond visiting the malicious website while SiYuan is running.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Vulnerable files:**
- `kernel/server/serve.go`, lines 960-963 — CORS middleware
- `kernel/api/snippet.go`, lines 93-128 — snippet injection endpoint&lt;/p&gt;
&lt;p&gt;**Root cause:** The CORS middleware unconditionally sets:
```
Access-Control-Allow-Origin: *
Access-Control-Allow-Credentials: true
Access-Control-Allow-Private-Network: true
```&lt;/p&gt;
&lt;p&gt;The `Access-Control-Allow-Private-Network: true` header explicitly opts into Chrome&amp;#39;s Private Network Access specification, telling the browser that external websites are permitted to access this localhost service. Combined with `Access-Control-Allow-Origin: *`, any website on the internet can make authenticated cross-origin requests to the SiYuan API at `127.0.0.1:6806`.&lt;/p&gt;
&lt;p&gt;The auth middleware at `kernel/model/session.go:251-280` checks the `Origin` header, but this check is bypassed because the browser sends the session cookie (set on `127.0.0.1`) along with the cross-origin request, and the server validates the cookie before reaching the Origin check for un…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-68p4-j234-43mv</guid>
    </item>
  </channel>
</rss>
