Path Traversal Vulnerability in SiYuan Product by SiYuan
CVE-2026-87815
8.4HIGH
What is CVE-2026-87815?
SiYuan versions prior to v3.8.2 are vulnerable to a path traversal exploit in the /api/riff/removeRiffDeck endpoint. The flaw arises from a lack of validation for the deckID parameter, allowing an authenticated administrator to introduce path traversal sequences. This can lead to unauthorized deletion of .deck and .cards files located outside the designated workspace directory, posing significant risks to data integrity.
Affected Version(s)
siyuan 0 < 3.8.2
siyuan 3.8.2
