SiYuan是SiYuan开源的一个隐私至上的个人知识管理系统。 SiYuan 3.6.2之前版本存在安全漏洞,该漏洞源于/appearance/*filepath端点路径清理不当,可能导致目录遍历和任意文件读取。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | < 3.6.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated file-serving endpoint under `/appearance/*filepath.` Due to improper path sanitization, attackers can perform directory traversal and read arbitrary files accessible to the server process. Authentication checks explicitly exclude this endpoint, allowing exploitation without valid credentials. Version 3.6.2 fixes this issue. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-33476.yaml | POC Details |
| CVE-2026-32938 | 9.9 CRITICAL | SiYuan has an Arbitrary File Read in its Desktop Publish Service |
| CVE-2026-32767 | 9.8 CRITICAL | SiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search API |
| CVE-2026-32940 | 9.3 CRITICAL | SiYuan has a SanitizeSVG bypass via data:text/xml in getDynamicIcon (incomplete fix for CV |
| CVE-2026-33203 | 7.5 HIGH | SiYuan has an Unauthenticated WebSocket DoS via Auth Keepalive Bypass |
| CVE-2026-33194 | 6.8 MEDIUM | SiYuan has an Incomplete Fix for IsSensitivePath Denylist Allows File Read from /opt, /usr |
| CVE-2026-33067 | SiYuan has Stored XSS to RCE via Unsanitized Bazaar Package Metadata | |
| CVE-2026-33066 | SiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering |
No comments yet