Arbitrary File Deletion Vulnerability in SiYuan by SiYuan Note
CVE-2026-60084
8.4HIGH
What is CVE-2026-60084?
SiYuan versions prior to v3.7.4 are susceptible to an arbitrary file deletion vulnerability. This issue arises from the /api/search/removeTemplate endpoint, which accepts an unvalidated path parameter. Authenticated admin users can exploit this vulnerability to provide absolute filesystem paths, enabling them to recursively delete files or directories that the kernel process has permission to remove. As a result, this can lead to severe data loss and compromise the integrity of the host filesystem.
Affected Version(s)
siyuan 0 < 3.7.4
siyuan 3.7.4
