PT-2026-28170 · Siyuan · Siyuan
Congsec
·
Publicado
2026-03-25
·
Atualizado
2026-03-27
·
CVE-2026-33669
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.6.2
Description
The SiYuan personal knowledge management system prior to version 3.6.2 had a flaw where document IDs were retrieved via the
/api/file/readDir interface, and then the /api/block/getChildBlocks interface was used to view the content of all documents. This allowed unauthorized access to potentially encrypted or prohibited documents under the publishing service. The /api/block/getChildBlocks API Endpoint is used to retrieve document content, taking the id variable as input.Recommendations
Versions prior to 3.6.2 should be updated to version 3.6.2 or later.
Exploit
Correção
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Siyuan