PT-2026-85483 · Siyuan · Siyuan

CVE-2026-85583

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.8.2
Description A path traversal issue exists in the file-read endpoint accessible to users with the reader role. The system follows symbolic links (symlinks) when opening authorized asset paths under data/assets/. This allows an attacker to request a logical asset that is a symlink to a file located outside the workspace, enabling them to retrieve the target file bytes and bypass workspace boundary restrictions.
Recommendations Update to version 3.8.2 or later.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85583
GHSA-G7GF-V79M-JWRM

Affected Products

Siyuan