PT-2026-99308 · Siyuan · Siyuan
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.8.4
Description
A path traversal issue exists in the 'checkoutRepo' endpoint. Authenticated administrators can overwrite arbitrary JSON files in pre-existing kernel-writable directories outside the workspace boundaries by providing directory traversal sequences in the
sessionID parameter. Path traversal is a flaw that allows an attacker to access files and directories that are stored outside the web root folder.Recommendations
Update SiYuan to version 3.8.4 or later.
Avoid using the
sessionID parameter in the 'checkoutRepo' endpoint with untrusted input until the update is applied.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan