Unauthorized Deletion Vulnerability in SiYuan Personal Knowledge Management System
CVE-2026-40259
8.1HIGH
What is CVE-2026-40259?
A vulnerability in SiYuan, an open-source personal knowledge management system, allows authenticated users with limited privileges to delete arbitrary attribute view definitions. The issue arises from the /api/av/removeUnusedAttributeView endpoint, which is inadequately protected, allowing misuse of tokens to bypass necessary permission checks. Users can exploit this flaw by accessing publicly exposed data points, leading to unintentional deletion of essential workspace components and potential disruption of database functionalities. This vulnerability was addressed in version 3.6.4.
Affected Version(s)
siyuan < 0.0.0-20260407035653-2f416e5253f1 < 0.0.0-20260407035653-2f416e5253f1
siyuan < 3.6.4 < 3.6.4
