Path Guard Bypass Vulnerability in SiYuan by SiYuan Team
CVE-2026-85580
7.1HIGH
What is CVE-2026-85580?
SiYuan versions before v3.8.2 are vulnerable to a path guard bypass that allows attackers to exploit case-sensitive file name discrepancies on Linux file systems. By manipulating case variants of file paths, such as requesting 'PublishAccess.json', unauthorized parties can gain access to sensitive publish-access configuration settings and metadata, posing a significant security risk.
Affected Version(s)
siyuan 0 < 3.8.2
siyuan 3.8.2
