


Perceptive Security
SOC/SIEM Consultancy

SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers to construct travers…
Published:
2 augustus 2026 om 22:00:00
Alert date:
3 augustus 2026 om 15:06:10
Source:
nvd.nist.gov
Web Technologies, Database & Storage, Data Breach & Exfiltration
SiYuan versions prior to v3.7.3 contain a path traversal vulnerability due to missing validation of the avID parameter in attribute-view read endpoints. Attackers can craft traversal paths that escape the designated storage directory. The vulnerability affects authenticated users with RoleReader permissions as well as anonymous clients when publish authentication is disabled. Exploitation allows reading arbitrary JSON files outside the attribute-view directory, leading to disclosure of cross-scope database content. The issue exists across all code branches of the affected endpoints. A fix was introduced in SiYuan v3.7.3. The vulnerability is tracked as CVE-2026-69086 and has been disclosed via GitHub Security Advisories and VulnCheck.
Technical details
Mitigation steps:
Affected products:
SiYuan before v3.7.3
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-69086
https://github.com/siyuan-note/siyuan/security/advisories/GHSA-7hm9-v7vf-7g4w
https://www.vulncheck.com/advisories/siyuan-before-path-traversal-via-unvalidated-avid
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
