PT-2026-33210 · Siyuan · Siyuan

CVE-2026-40318

·

Published

2026-04-10

·

Updated

2026-07-30

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.6.4
Description The '/api/av/removeUnusedAttributeView' endpoint constructs a filesystem path using the user-controlled id parameter without validation or path boundary enforcement. This allows an attacker to inject path traversal sequences, such as '../', to escape the intended directory and delete arbitrary .json files on the server, including global configuration files and workspace metadata. Path traversal is a technique used to access files and directories that are stored outside the web root folder.
Recommendations Update to version 3.6.4. As a temporary workaround, avoid using the id parameter in the '/api/av/removeUnusedAttributeView' endpoint until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40318
GHSA-VW86-C94W-V3X4
GO-2026-5679
OPENSUSE-SU-2026:21483-1

Affected Products

Siyuan