File Path Manipulation Vulnerability in SiYuan Note by SiYuan Technologies
CVE-2026-82651

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
30 August 2026

What is CVE-2026-82651?

The SiYuan Note application, prior to version 3.8.1, contains a vulnerability where it fails to enforce path restrictions on certain administrative endpoints. Specifically, the /history/* and /repo/diff/* endpoints do not properly apply the IsForbiddenAbsPath guard. This oversight allows authenticated administrators to access historical snapshots and sensitive files, including plaintext publish-mode passwords and other confidential data located in directories such as data/.siyuan/publishAccess.json. This could lead to unauthorized data exposure, making it critical for administrators to upgrade to the latest version to mitigate the risks associated with this vulnerability.

Affected Version(s)

siyuan 0 < 3.8.1

siyuan 3.8.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

alham-rizvi
.