PT-2026-57007 · Siyuan · Siyuan
CVE-2026-59832
·
Published
2026-07-09
·
Updated
2026-09-10
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.7.1
Description
An authenticated user can read workspace secrets and the document database. This occurs because the
/snippets/*filepath endpoint uses the serveSnippets() function in kernel/server/serve.go, which joins a single-decoded request path with the snippets directory without performing subpath containment or sensitive-path checks. This allows for path traversal via the filepath variable.Recommendations
Update to version 3.7.1.
Exploit
Fix
Path traversal
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Siyuan