CVE-2026-100634
Last modified
CVE-2026-100634 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. SiYuan before v3.8.4 does not validate the sender or restrict recipients in the 'siyuan-send-windows' IPC handler of the Electron main process (app/electron/main.js). The handler ignores event.sender and forwards any received payload to every BrowserWindow returned by BrowserWindow.getAllWindows(), including windows belonging to other opened workspaces.
Description
SiYuan before v3.8.4 does not validate the sender or restrict recipients in the 'siyuan-send-windows' IPC handler of the Electron main process (app/electron/main.js). The handler ignores event.sender and forwards any received payload to every BrowserWindow returned by BrowserWindow.getAllWindows(), including windows belonging to other opened workspaces. A renderer connected to an attacker-controlled remote kernel can therefore send {cmd: "lockscreenByMode"} and have it delivered across the workspace boundary; a sibling workspace window whose lockScreenMode is set to 1 invokes lockScreen(). Repeated messages allow the remote workspace to repeatedly lock unrelated local workspace windows, causing a limited denial of service. No confidentiality, integrity, or code-execution impact was observed.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-100634?
How severe is CVE-2026-100634?
How do I fix CVE-2026-100634?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-100629Capgo (capgo.app backend) before 12.127.5 contains an author…5.5
- CVE-2026-10063A vulnerability was identified in TRENDnet TEW-432BRP 3.10B2…9.8
- CVE-2026-100630AVideo contains a stored cross-site scripting vulnerability …5.4
- CVE-2026-100631Parse Server is an open source backend server. In versions p…7.5
- CVE-2026-100632Parse Server is an open-source backend server. In versions >…6.5
- CVE-2026-100633SiYuan is a self-hosted personal knowledge management system…6.5
- CVE-2026-100635SiYuan before v3.8.4 contains an authentication bypass vulne…5.9
- CVE-2026-100636SiYuan versions before v3.8.4 contain a path traversal vulne…7.6
- CVE-2026-100637SiYuan versions before v3.8.4 contain a path traversal vulne…7.6
- CVE-2026-100638SiYuan versions before v3.8.4 contain a path traversal vulne…7.6
- CVE-2026-100639SiYuan v3.8.3 fails to HTML-escape the data-subtype attribut…8.8
- CVE-2026-10064A security flaw has been discovered in TRENDnet TEW-432BRP 3…9.8
Are you affected by CVE-2026-100634?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
