Junglewise Threat Intelligence

CVE-2026-100640: SiYuan authorization omission in siyuan-get IPC handler

CVE-2026-100640 · Severity: medium · CVSS 4.7 · Published 2026-09-26

Technologies: SiYuan Note SiYuan. Vendors: SiYuan Note.

Executive brief

SiYuan is a note-taking and knowledge management application that stores documents and supports rich text features. Before version 3.8.4, a flaw in the inter-process communication (IPC) handler fails to properly restrict remote renderer access, allowing an attacker who controls or serves content in the application's remote window to extract sensitive clipboard data including formatted documents, spreadsheets, and formula content during paste operations. This could expose confidential document fragments or embedded data to malicious content running within the application.

Technical details

The vulnerability is an authorization omission in the siyuan-get IPC handler where clipboardReadMathML, clipboardReadOffice, and clipboardReadWPS commands lack the remote-sender guard present on neighboring clipboard commands. A remote-kernel renderer can invoke these commands with plaintext matching the user's clipboard during a user-mediated paste operation to extract native clipboard formats. The attack requires user interaction (paste action) but allows silent data exfiltration across the remote-renderer-to-native-clipboard boundary.

Affected products

  • siyuan-note SiYuan before 3.8.4

Timeline

  • 2026-09-26: disclosed
  • 2026-09-26: patched: version 3.8.4 released

References

Related threats