Unauthorized Deletion Vulnerability in SiYuan Personal Knowledge Management System
CVE-2026-40259

8.1HIGH

Key Information:

Status
Vendor
CVE Published:
16 April 2026

What is CVE-2026-40259?

A vulnerability in SiYuan, an open-source personal knowledge management system, allows authenticated users with limited privileges to delete arbitrary attribute view definitions. The issue arises from the /api/av/removeUnusedAttributeView endpoint, which is inadequately protected, allowing misuse of tokens to bypass necessary permission checks. Users can exploit this flaw by accessing publicly exposed data points, leading to unintentional deletion of essential workspace components and potential disruption of database functionalities. This vulnerability was addressed in version 3.6.4.

Affected Version(s)

siyuan < 0.0.0-20260407035653-2f416e5253f1 < 0.0.0-20260407035653-2f416e5253f1

siyuan < 3.6.4 < 3.6.4

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.