PT-2026-28170 · Siyuan · Siyuan

Congsec

·

Publicado

2026-03-25

·

Atualizado

2026-03-27

·

CVE-2026-33669

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.6.2
Description The SiYuan personal knowledge management system prior to version 3.6.2 had a flaw where document IDs were retrieved via the /api/file/readDir interface, and then the /api/block/getChildBlocks interface was used to view the content of all documents. This allowed unauthorized access to potentially encrypted or prohibited documents under the publishing service. The /api/block/getChildBlocks API Endpoint is used to retrieve document content, taking the id variable as input.
Recommendations Versions prior to 3.6.2 should be updated to version 3.6.2 or later.

Exploit

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33669
GHSA-34XJ-66V3-6J83
GO-2026-4842
SUSE-SU-2026:1135-1

Produtos afetados

Siyuan