<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 08:05:08 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-330238</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-330238</link>
      <description>EUVD-2026-330238</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-330238</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54069</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54069</link>
      <description>&lt;p&gt;SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan Note&amp;#39;s kernel HTTP server unconditionally trusts all chrome-extension:// origins, granting RoleAdministrator access to every installed browser extension without any authentication. Combined with the default empty AccessAuthCode on desktop installs, any Chrome/Chromium extension -- including a compromised legitimate extension via supply chain attack -- can make fully authenticated admin API calls to the SiYuan kernel at 127.0.0.1:6806, enabling data exfiltration, stored XSS injection, and configuration tampering. This vulnerability is fixed in 3.7.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan Note&amp;#39;s kernel HTTP server unconditionally trusts all chrome-extension:// origins, granting RoleAdministrator access to every installed browser extension without any authentication. Combined with the default empty AccessAuthCode on desktop installs, any Chrome/Chromium extension -- including a compromised legitimate extension via supply chain attack -- can make fully authenticated admin API calls to the SiYuan kernel at 127.0.0.1:6806, enabling data exfiltration, stored XSS injection, and configuration tampering. This vulnerability is fixed in 3.7.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54069</guid>
    </item>
    <item>
      <title>GHSA-hvr9-72v2-fff3 — SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hvr9-72v2-fff3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;SiYuan Note&amp;#39;s kernel HTTP server unconditionally trusts all `chrome-extension://` origins, granting `RoleAdministrator` access to every installed browser extension without any authentication. Combined with the default empty `AccessAuthCode` on desktop installs, any Chrome/Chromium extension -- including a compromised legitimate extension via supply chain attack -- can make fully authenticated admin API calls to the SiYuan kernel at `127.0.0.1:6806`, enabling data exfiltration, stored XSS injection, and configuration tampering.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;SiYuan &amp;lt;= v3.6.5 (commit `96dfe0bea474`). The chrome-extension allowlist remains unfixed as of the latest commit on the fix branch (`d7b77d945e0d`).&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;### Blanket chrome-extension:// Origin Trust (CWE-346)&lt;/p&gt;
&lt;p&gt;In `kernel/model/session.go:277`, the `CheckAuth` middleware exempts all `chrome-extension://` origins from authentication:&lt;/p&gt;
&lt;p&gt;```go
if strings.HasPrefix(origin, &amp;#34;chrome-extension://&amp;#34;) {
    // skip auth
}
```&lt;/p&gt;
&lt;p&gt;At `session.go:284`, the request is assigned `RoleAdministrator`:&lt;/p&gt;
&lt;p&gt;```go
c.Set(&amp;#34;role&amp;#34;, model.RoleAdministrator)
```&lt;/p&gt;
&lt;p&gt;The `AccessAuthCode` field defaults to an empty string for desktop installs (`ContainerStd`). When empty, no token validation occurs. This means **any** Chrome/Chromium extension can make fully authenticated admin API calls to the SiYuan kernel.&lt;/p&gt;
&lt;p&gt;The origin check trusts the entire `chrome-extension://` scheme rather than validating a specific extension ID, so every insta…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;SiYuan Note&amp;#39;s kernel HTTP server unconditionally trusts all `chrome-extension://` origins, granting `RoleAdministrator` access to every installed browser extension without any authentication. Combined with the default empty `AccessAuthCode` on desktop installs, any Chrome/Chromium extension -- including a compromised legitimate extension via supply chain attack -- can make fully authenticated admin API calls to the SiYuan kernel at `127.0.0.1:6806`, enabling data exfiltration, stored XSS injection, and configuration tampering.&lt;/p&gt;
&lt;p&gt;## Affected Versions&lt;/p&gt;
&lt;p&gt;SiYuan &amp;lt;= v3.6.5 (commit `96dfe0bea474`). The chrome-extension allowlist remains unfixed as of the latest commit on the fix branch (`d7b77d945e0d`).&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;### Blanket chrome-extension:// Origin Trust (CWE-346)&lt;/p&gt;
&lt;p&gt;In `kernel/model/session.go:277`, the `CheckAuth` middleware exempts all `chrome-extension://` origins from authentication:&lt;/p&gt;
&lt;p&gt;```go
if strings.HasPrefix(origin, &amp;#34;chrome-extension://&amp;#34;) {
    // skip auth
}
```&lt;/p&gt;
&lt;p&gt;At `session.go:284`, the request is assigned `RoleAdministrator`:&lt;/p&gt;
&lt;p&gt;```go
c.Set(&amp;#34;role&amp;#34;, model.RoleAdministrator)
```&lt;/p&gt;
&lt;p&gt;The `AccessAuthCode` field defaults to an empty string for desktop installs (`ContainerStd`). When empty, no token validation occurs. This means **any** Chrome/Chromium extension can make fully authenticated admin API calls to the SiYuan kernel.&lt;/p&gt;
&lt;p&gt;The origin check trusts the entire `chrome-extension://` scheme rather than validating a specific extension ID, so every insta…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hvr9-72v2-fff3</guid>
    </item>
  </channel>
</rss>
