216.73.216.6

CVE-2026-41894

· Published 24/04/2026 19:17 · Modified 24/04/2026 19:17

Labels: CVE-2026-41894 2026-04-24CVE-2026-41894CWE-22[email protected]

Essential information

Published
24/04/2026 19:17
Modified
24/04/2026 19:17
Author
Creator
CVSS
7.1 HIGH (v3) 7.1 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, the fix for CVE-2026-30869 only added a denylist check (IsSensitivePath) but did not address the root cause — a redundant url.PathUnescape() call in serveExport(). An authenticated attacker can use double URL encoding (%252e%252e) to traverse directories and read arbitrary workspace files including the full SQLite database (siyuan.db), kernel log, and all user documents. This vulnerability is fixed in 3.6.5.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
siyuan / siyuan cpe:2.3:a:siyuan:siyuan:<3.6.5:*:*:*:*:*:*:*

References