Path Traversal Vulnerability in SiYuan 3.8.0 by SiYuan Note
CVE-2026-82650
5.9MEDIUM
What is CVE-2026-82650?
In SiYuan version 3.8.0, an authenticated user can exploit a path traversal vulnerability present in the RenderTemplate function. This security flaw permits attackers to access sensitive files within the workspace directory through the POST /api/template/render endpoint. Unlike the safeguards in the file API, the current implementation fails to adequately restrict access to sensitive paths. As a result, attackers could read files such as conf/conf.json, which contains critical information like API tokens and cookie signing keys. This vulnerability has been addressed in version 3.8.1.
Affected Version(s)
siyuan 0 < 3.8.1
siyuan 3.8.1
