PT-2026-85483 · Siyuan · Siyuan
CVE-2026-85583
·
Published
2026-09-04
·
Updated
2026-09-04
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.8.2
Description
A path traversal issue exists in the file-read endpoint accessible to users with the reader role. The system follows symbolic links (symlinks) when opening authorized asset paths under
data/assets/. This allows an attacker to request a logical asset that is a symlink to a file located outside the workspace, enabling them to retrieve the target file bytes and bypass workspace boundary restrictions.Recommendations
Update to version 3.8.2 or later.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan