SiYuan 在 v3.8.2 之前的版本中存在一个路径遍历漏洞。该漏洞位于“读取端点(reader-accessible file-read endpoint)”中,该端点在打开受权限控制的资产路径时会跟随符号链接(symlinks)。拥有“阅读者(reader)”角色的攻击者可以请求 下的一个逻辑资产,若该资产是一个指向工作区外文件的符号链接,则能够获取目标文件的内容,从而绕过工作区边界限制。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| siyuan-note | siyuan | < 3.8.2 |
affected |
3.8.2 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.8.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85584 | 7.5 HIGH | SiYuan before v3.8.2 Denial of Service via Auth Throttle |
| CVE-2026-85581 | 7.5 HIGH | SiYuan before v3.8.2 Denial of Service via unauthenticated UI-process registration |
| CVE-2026-85585 | 7.5 HIGH | SiYuan before v3.8.2 Unbounded Memory Consumption via ControlConcurrency |
| CVE-2026-85578 | 6.5 MEDIUM | SiYuan through 3.8.1 Authorization Bypass via getFile |
| CVE-2026-85582 | 6.5 MEDIUM | SiYuan before v3.8.2 Unbounded Session Creation via Basic Auth |
| CVE-2026-85580 | 6.5 MEDIUM | SiYuan before v3.8.2 Path Guard Bypass via Case Mismatch |
| CVE-2026-85579 | 4.3 MEDIUM | SiYuan before v3.8.2 Information Disclosure via undoState |
No comments yet