CVE-2026-34449Disclosure(b3log / siyuan)

LOWCVSS 9.6 · CRITICAL

Exploit discussion active in current signal (5 latest mentions)

Immediate actions

  • Patch b3log siyuan systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting the permissive CORS policy (Access-Control-Allow-Origin: * + Access-Control-Allow-Private-Network: true) to inject a JavaScript snippet via the API. The injected snippet executes in Electron's Node.js context with full OS access the next time the user opens SiYuan's UI. No user interaction is required beyond visiting the malicious website while SiYuan is running. This issue has been patched in version 3.6.2.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-942

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • siyuan

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked at 5 mentions on most recent observed day (2026-04-01)
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
siyuan

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-03-31: 1Mentions · 2026-04-01: 5PoC Mentioned / Linked · 2026-04-01: 1Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 503-3104-01
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-311
Patch1
2026-04-015
Disclosure5
Full discourse6 posts
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34449: SiYuan: Cross-Origin RCE via Per... CORS wildcard + private network access = instant RCE when you browse the web with SiYuan running - Electron's Node.js c... https://zerodaysignal.com/vulnerability/CVE-2026-34449 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-34449, describing a Cross-Origin Remote Code Execution in SiYuan and linking to a ZeroDaySignal article that likely contains a PoC, but offers no evidence of active exploitation, patches, or false positives.

    0001096
    194 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34449 SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by… https://www.cve.org/CVERecord?id=CVE-2026-34449

    Post summary

    CVE‑2026‑34449 threatens SiYuan users by enabling RCE via a malicious website on versions below 3.6.2.

    00000113
    56.9K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `SiYuan` is affected by a cross-origin RCE vulnerability via permissive CORS policy and JS snippet injection (CVE-2026-34449). Review `SiYuan` configurations. #RCE #CORS #Security https://www.pulsepatch.io/posts/cve-2026-34449-siyuan-cross-origin-rce-vulnerability

    Post summary

    The post announces CVE‑2026‑34449 in SiYuan, detailing a cross‑origin RCE enabled by permissive CORS, but offers no PoC, exploit, active attack evidence, or patch information.

    0000027
    6 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34449 SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting the permissive CORS ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34449

    Post summary

    The content announces a Remote Code Execution vulnerability (CVE-2026-34449) in SiYuan before version 3.6.2, detailing a permissive CORS-based attack vector, but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000064
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-34449 - Critical SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code Execution (RCE) on any desktop running SiYuan by exploiting the permi... https://www.thehackerwire.com/vulnerability/CVE-2026-34449/ https://t.co/oymXz6cPLl

    Post summary

    The post announces CVE-2026-34449 as a critical RCE vulnerability affecting SiYuan before version 3.6.2, providing technical details but no PoC, exploit code, patch, or evidence of active exploitation.

    0000051
    163 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34449: CRITICAL] Attention: SiYuan personal knowledge management system users! Protect your data - Update to version 3.6.2 to patch a critical security flaw allowing Remote Code Execution via malic...#cve,CVE-2026-34449,#cybersecurity https://cvefind.com/CVE-2026-34449

    Post summary

    The tweet alerts SiYuan users to a critical RCE vulnerability (CVE‑2026‑34449) and urges them to update to version 3.6.2.

    0000049
    617 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appb3logsiyuan---

Explore more