PT-2026-83576 · Siyuan · Siyuan
CVSS v4.0
5.9
Medium
| Vector | AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SiYuan version 3.8.0
Description
An authenticated attacker can exploit a path traversal and sensitive file exposure issue through the
RenderTemplate() function. This is reachable via the 'POST /api/template/render' endpoint. While the system restricts paths to the workspace directory using util.IsAbsPathInWorkspace, it fails to apply a sensitive-path exclusion blocklist. This allows the unauthorized reading of sensitive workspace files, such as conf/conf.json, which stores the API token and cookie signing key.Recommendations
Update SiYuan to version 3.8.1.
Exploit
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan