Path Traversal Vulnerability in SiYuan Knowledge Management System
CVE-2026-54066
7.5HIGH
What is CVE-2026-54066?
The SiYuan Knowledge Management System prior to version 3.7.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to access arbitrary files in the WorkspaceDir, including sensitive configuration files and database information. This occurs through double-URL-encoding manipulation of URL segments on the /assets/*path route. The issue was previously partially addressed in relation to the /export/ route, but the underlying vulnerability persists. The flaw has been rectified in version 3.7.0.
Affected Version(s)
siyuan < 3.7.0
