VYPR
Critical severityNVD Advisory· Published Mar 26, 2026· Updated Mar 27, 2026

SiYuan has Arbitrary Document Reading within the Publishing Service

CVE-2026-33669

Description

SiYuan is a personal knowledge management system. Prior to version 3.6.2, document IDs were retrieved via the /api/file/readDir interface, and then the /api/block/getChildBlocks interface was used to view the content of all documents. Version 3.6.2 patches the issue.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/siyuan-note/siyuan/kernelGo
<= 0.0.0-20260317012524-fe4523fff2c8
github.com/siyuan-note/siyuan/kernelGo
>= 0

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.