top of page
perceptive_background_267k.jpg

SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers to construct travers…

Published:

2 augustus 2026 om 22:00:00

Alert date:

3 augustus 2026 om 15:06:10

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage, Data Breach & Exfiltration

SiYuan versions prior to v3.7.3 contain a path traversal vulnerability due to missing validation of the avID parameter in attribute-view read endpoints. Attackers can craft traversal paths that escape the designated storage directory. The vulnerability affects authenticated users with RoleReader permissions as well as anonymous clients when publish authentication is disabled. Exploitation allows reading arbitrary JSON files outside the attribute-view directory, leading to disclosure of cross-scope database content. The issue exists across all code branches of the affected endpoints. A fix was introduced in SiYuan v3.7.3. The vulnerability is tracked as CVE-2026-69086 and has been disclosed via GitHub Security Advisories and VulnCheck.

Technical details

Mitigation steps:

Affected products:

SiYuan before v3.7.3

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page