Back

HIGH

SiYuan before v3.7.4 Authentication Bypass via Localhost Trust

Published Aug 12, 2026

Description

SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the administrator role (RoleAdministrator) to any request whose RemoteAddr is loopback (127.0.0.1) for a specific set of endpoints (including /api/system/exit, getNetwork, getWorkspaceInfo, /assets/*, and /export/*). These localhost bypasses sit outside the access auth code gate, so they apply even when an access auth code is configured. Because the fixed-port reverse proxy forwards requests to the kernel over loopback without injecting an authentication token and does not configure trusted proxies, a request forwarded through this proxy reaches the kernel with RemoteAddr = 127.0.0.1. If the fixed-port proxy is bound to a network interface, this could allow a remote unauthenticated attacker to obtain admin access on the affected endpoints; however, per the advisory this remote forwarding behavior was established only by code inspection and was not reproduced end-to-end.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulnCheck
Published Aug 12, 2026
Updated Aug 14, 2026
Reserved Aug 10, 2026

CISA Vulnrichment

Updated Aug 14, 2026

NVD

Status Deferred
Modified Aug 26, 2026

Red Hat

No data

ENISA EUVD

Assigner VulnCheck
Published Aug 12, 2026
Updated Aug 14, 2026