File Path Manipulation Vulnerability in SiYuan Note by SiYuan Technologies
CVE-2026-82651
6.9MEDIUM
What is CVE-2026-82651?
The SiYuan Note application, prior to version 3.8.1, contains a vulnerability where it fails to enforce path restrictions on certain administrative endpoints. Specifically, the /history/* and /repo/diff/* endpoints do not properly apply the IsForbiddenAbsPath guard. This oversight allows authenticated administrators to access historical snapshots and sensitive files, including plaintext publish-mode passwords and other confidential data located in directories such as data/.siyuan/publishAccess.json. This could lead to unauthorized data exposure, making it critical for administrators to upgrade to the latest version to mitigate the risks associated with this vulnerability.
Affected Version(s)
siyuan 0 < 3.8.1
siyuan 3.8.1
