PT-2026-79544 · Siyuan · Siyuan
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.7.4
Description
An arbitrary file deletion flaw exists in the
/api/search/removeTemplate endpoint. The application fails to validate the path parameter, which is passed directly to the os.RemoveAll() function. This allows authenticated administrators to provide absolute filesystem paths to recursively delete any file or directory that the kernel process has permission to remove on the host filesystem.Recommendations
Update SiYuan to version 3.7.4 or later.
As a temporary mitigation, restrict access to the
/api/search/removeTemplate endpoint.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan