PT-2026-99309 · Siyuan · Siyuan

·

CVE-2026-100638

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.8.4
Description An issue exists in the 'setNotebookIcon' endpoint that allows authenticated administrators to perform path traversal, a technique used to access files and directories that are stored outside the web root folder. By providing directory traversal sequences in the notebook parameter, an attacker can escape the workspace data directory to create arbitrary directory trees and write conf.json files to any location accessible by the kernel process.
Recommendations Update to version 3.8.4 or later. Avoid using the notebook parameter in the 'setNotebookIcon' endpoint until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100638
GHSA-6H8X-6MPH-7438

Affected Products

Siyuan