CVE-2026-100640
Last modified
CVE-2026-100640 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. SiYuan before v3.8.4 contains an authorization omission in the siyuan-get IPC handler that allows remote-kernel renderers to access native clipboard formats by invoking clipboardReadMathML, clipboardReadOffice, and clipboardReadWPS commands with matching plaintext. Attackers controlling remote renderer content can obtain MathML formulas, Office bytes, and WPS bytes from local clipboard during user-mediated paste operations..
Description
SiYuan before v3.8.4 contains an authorization omission in the siyuan-get IPC handler that allows remote-kernel renderers to access native clipboard formats by invoking clipboardReadMathML, clipboardReadOffice, and clipboardReadWPS commands with matching plaintext. Attackers controlling remote renderer content can obtain MathML formulas, Office bytes, and WPS bytes from local clipboard during user-mediated paste operations.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-100640?
How severe is CVE-2026-100640?
How do I fix CVE-2026-100640?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-100635SiYuan before v3.8.4 contains an authentication bypass vulne…5.9
- CVE-2026-100636SiYuan versions before v3.8.4 contain a path traversal vulne…7.6
- CVE-2026-100637SiYuan versions before v3.8.4 contain a path traversal vulne…7.6
- CVE-2026-100638SiYuan versions before v3.8.4 contain a path traversal vulne…7.6
- CVE-2026-100639SiYuan v3.8.3 fails to HTML-escape the data-subtype attribut…8.8
- CVE-2026-10064A security flaw has been discovered in TRENDnet TEW-432BRP 3…9.8
- CVE-2026-100641SiYuan before v3.8.4 does not HTML-escape stored flashcard b…8
- CVE-2026-100642SiYuan versions from v2.1.0 before v3.8.4 contain a cross-si…7.6
- CVE-2026-100643SiYuan versions before v3.8.4 fail to properly escape four s…8
- CVE-2026-100644SiYuan before v3.8.4 contains a SQL injection vulnerability …7.5
- CVE-2026-100645SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-si…8
- CVE-2026-100646SiYuan is a self-hosted personal knowledge management system…8.1
Are you affected by CVE-2026-100640?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
