CVE-2026-69086
Received Received - Intake

SiYuan Path Traversal in Attribute-View Endpoints

Vulnerability report for CVE-2026-69086, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: VulnCheck

Description

SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers to construct traversal paths that escape the storage directory. Authenticated users with RoleReader permissions or anonymous clients when publish authentication is disabled can read JSON files outside the attribute-view directory to disclose cross-scope database content.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
siyuan siyuan to 3.7.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SiYuan versions before v3.7.3 have a flaw where the avID parameter is not properly validated in attribute-view read endpoints. This allows attackers to use path traversal to access files outside the intended storage directory. The issue affects authenticated users with RoleReader permissions or anonymous clients if publish authentication is disabled.

Impact Analysis

An attacker could exploit this to read sensitive JSON files outside the attribute-view directory, potentially exposing cross-scope database content. This may lead to unauthorized data disclosure, including confidential or proprietary information.

Compliance Impact

This vulnerability could result in unauthorized access to personal or sensitive data, violating GDPR and HIPAA compliance requirements. Organizations may face legal penalties, reputational damage, and loss of trust due to data breaches.

Mitigation Strategies

Upgrade SiYuan to version v3.7.3 or later to address the avID parameter validation issue in attribute-view read endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-69086. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart