PT-2026-99309 · Siyuan · Siyuan
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.8.4
Description
An issue exists in the 'setNotebookIcon' endpoint that allows authenticated administrators to perform path traversal, a technique used to access files and directories that are stored outside the web root folder. By providing directory traversal sequences in the
notebook parameter, an attacker can escape the workspace data directory to create arbitrary directory trees and write conf.json files to any location accessible by the kernel process.Recommendations
Update to version 3.8.4 or later.
Avoid using the
notebook parameter in the 'setNotebookIcon' endpoint until the update is applied.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan