A AegiFlow
HIGHCVSS 8.3EPSS 0.4%

CVE-2026-69086

CVE-2026-69086 updated by NVD

Published
2026-09-03
Modified
2026-09-03
EPSS percentile
28%
Sources
github-advisory, nvd

Summary

SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers to construct traversal paths that escape the storage directory. Authenticated users with RoleReader permissions or anonymous clients when publish authentication is disabled can read JSON files outside the attribute-view directory to disclose cross-scope database content.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/siyuan-note/siyuan/kernel0.0.0-20260720151813-0f5a0e7c67b0

Remediation: Upgrade to 0.0.0-20260720151813-0f5a0e7c67b0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.