CVE-2026-87815
Deferred Deferred - Pending Action

Path Traversal in SiYuan Prior to v3.8.2

Vulnerability report for CVE-2026-87815, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck endpoint that fails to validate the deckID parameter. An authenticated administrator can supply path traversal sequences to delete arbitrary .deck and .cards files outside the workspace directory.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
siyuan siyuan to 3.8.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in SiYuan versions before v3.8.2 affecting the /api/riff/removeRiffDeck endpoint. The deckID parameter is not properly validated, allowing authenticated administrators to delete arbitrary .deck and .cards files outside the workspace directory by supplying path traversal sequences like ../../../../../.

Detection Guidance

To detect this vulnerability, monitor for unauthorized file deletions or suspicious POST requests to the /api/riff/removeRiffDeck endpoint. Check logs for path traversal sequences like ../../ in the deckID parameter. Use network monitoring tools to inspect HTTP requests targeting this endpoint.

Impact Analysis

An attacker with admin privileges could delete important files outside the intended workspace, leading to data loss or disruption of note-taking functionality. This could affect personal or shared workspaces on the same system.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling unauthorized deletion of sensitive files. GDPR requires protection of personal data integrity, while HIPAA mandates safeguarding protected health information. Unauthorized file deletion may violate these requirements by compromising data availability and integrity.

Mitigation Strategies

Immediately upgrade SiYuan to version 3.8.2 or later. If upgrading is not possible, restrict access to the /api/riff/removeRiffDeck endpoint to trusted administrators only. Implement input validation to ensure deckID only contains valid node IDs. Review and remove any unnecessary admin privileges.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87815. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart