PT-2026-52107 · Siyuan · Siyuan

CVE-2026-54066

·

Published

2026-06-24

·

Updated

2026-07-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.7.0
Description An unauthenticated remote attacker can read arbitrary files within the WorkspaceDir when the system is in publish mode, which is an anonymous read-only HTTP endpoint. This is achieved by using double-URL-encoding on .. segments in the /assets/*path endpoint. Sensitive files that may be accessed include conf/conf.json (containing the AccessAuthCode SHA256 hash, API token, and sync keys), temp/siyuan.db, temp/blocktree.db, and siyuan.log.
Recommendations Update SiYuan to version 3.7.0.

Exploit

Fix

DoS

Path traversal

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54066
GHSA-P4M3-MGMM-C664
GO-2026-5964
OPENSUSE-SU-2026:21483-1

Affected Products

Siyuan