Path Traversal Vulnerability in SiYuan 3.8.0 by SiYuan Note
CVE-2026-82650

5.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
30 August 2026

What is CVE-2026-82650?

In SiYuan version 3.8.0, an authenticated user can exploit a path traversal vulnerability present in the RenderTemplate function. This security flaw permits attackers to access sensitive files within the workspace directory through the POST /api/template/render endpoint. Unlike the safeguards in the file API, the current implementation fails to adequately restrict access to sensitive paths. As a result, attackers could read files such as conf/conf.json, which contains critical information like API tokens and cookie signing keys. This vulnerability has been addressed in version 3.8.1.

Affected Version(s)

siyuan 0 < 3.8.1

siyuan 3.8.1

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

alham-rizvi
.