PT-2026-99307 · Siyuan · Siyuan
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.8.4
Description
A path traversal issue exists in the 'exportBrowserHTML' endpoint. Authenticated administrators can use directory traversal sequences in the
folder parameter to write arbitrary HTML content to an index.html file outside the workspace directory. This allows the overwriting of index.html in any location writable by the kernel, which can lead to stored Cross-Site Scripting (XSS)—a technique where malicious scripts are permanently stored on the target server—or workspace defacement.Recommendations
Update SiYuan to version 3.8.4 or later.
Avoid using the
folder parameter in the 'exportBrowserHTML' endpoint until the update is applied.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan