PT-2024-36572 · Siyuan · Siyuan

Elleuch-X1

·

Published

2024-12-11

·

Updated

2024-12-18

·

CVE-2024-55658

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.1.16
Description SiYuan is a personal knowledge management system. The /api/export/exportResources endpoint is vulnerable to arbitrary file read via path traversal. It is possible to manipulate the paths parameter to access and download arbitrary files from the host system by traversing the workspace directory structure.
Recommendations For versions prior to 3.1.16, update to version 3.1.16 to resolve the issue. As a temporary workaround, consider restricting access to the /api/export/exportResources endpoint until the update is applied. Avoid using the paths parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-55658
GHSA-25W9-WQFQ-GWQX
GO-2024-3323
OPENSUSE-SU-2024:14599-1

Affected Products

Siyuan