PT-2026-52107 · Siyuan · Siyuan
CVE-2026-54066
·
Published
2026-06-24
·
Updated
2026-07-30
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.7.0
Description
An unauthenticated remote attacker can read arbitrary files within the WorkspaceDir when the system is in publish mode, which is an anonymous read-only HTTP endpoint. This is achieved by using double-URL-encoding on
.. segments in the /assets/*path endpoint. Sensitive files that may be accessed include conf/conf.json (containing the AccessAuthCode SHA256 hash, API token, and sync keys), temp/siyuan.db, temp/blocktree.db, and siyuan.log.Recommendations
Update SiYuan to version 3.7.0.
Exploit
Fix
DoS
Path traversal
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Siyuan