PT-2026-99308 · Siyuan · Siyuan

·

CVE-2026-100637

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.8.4
Description A path traversal issue exists in the 'checkoutRepo' endpoint. Authenticated administrators can overwrite arbitrary JSON files in pre-existing kernel-writable directories outside the workspace boundaries by providing directory traversal sequences in the sessionID parameter. Path traversal is a flaw that allows an attacker to access files and directories that are stored outside the web root folder.
Recommendations Update SiYuan to version 3.8.4 or later. Avoid using the sessionID parameter in the 'checkoutRepo' endpoint with untrusted input until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100637
GHSA-JHMH-HR4G-C5G2

Affected Products

Siyuan