PT-2026-26689 · Siyuan Note · Siyuan

Published

2026-03-20

·

Updated

2026-03-20

·

CVE-2026-33476

CVSS v3.1

7.5

High

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated file-serving endpoint under /appearance/*filepath. Due to improper path sanitization, attackers can perform directory traversal and read arbitrary files accessible to the server process. Authentication checks explicitly exclude this endpoint, allowing exploitation without valid credentials. Version 3.6.2 fixes this issue.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-33476

Affected Products

Siyuan