Unrated severityOSV Advisory· Published Aug 3, 2026· Updated Aug 3, 2026
SiYuan before v3.7.3 Path Traversal via unvalidated avID
CVE-2026-69086
Description
SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers to construct traversal paths that escape the storage directory. Authenticated users with RoleReader permissions or anonymous clients when publish authentication is disabled can read JSON files outside the attribute-view directory to disclose cross-scope database content.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2v3.7.3-beta.2, v3.7.3-beta.1, v3.7.0-rc.2, …+ 1 more
- (no CPE)range: v3.7.3-beta.2, v3.7.3-beta.1, v3.7.0-rc.2, …
- (no CPE)range: <3.7.3
Patches
Vulnerability mechanics
References
2- github.com/siyuan-note/siyuan/security/advisories/GHSA-7hm9-v7vf-7g4wmitrevendor-advisory
- www.vulncheck.com/advisories/siyuan-before-path-traversal-via-unvalidated-avidmitrethird-party-advisory
News mentions
0No linked articles in our index yet.