Path Traversal Vulnerability in SiYuan Product by SiYuan Team
CVE-2026-65607
7.1HIGH
What is CVE-2026-65607?
Earlier versions of SiYuan (prior to v3.7.2) are vulnerable to a path traversal issue within the /export/temp/ endpoint of the serveExport handler. This flaw allows an authenticated attacker to exploit the absence of stringent path checks. By employing percent-encoded traversal characters, attackers can read sensitive files located outside of the designated TempDir, including essential system files such as /etc/passwd and private SSH keys. This vulnerability underscores the critical need for comprehensive path validations in file handling to prevent unauthorized access.
Affected Version(s)
siyuan 0 < 3.7.2
siyuan 3.7.2
