
Permissive CORS enables cross-origin Electron RCE in SiYuan
CVE-2026-34449 reports a critical cross-origin RCE affecting SiYuan `< 3.6.2`, where a malicious website can inject JavaScript via the API under a permissive CORS policy.
NewsWeb SecurityDesktop Security
1 minYesterday
