High severity7.7OSV Advisory· Published Aug 3, 2026· Updated Aug 26, 2026
CVE-2026-69086
CVE-2026-69086
Description
SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers to construct traversal paths that escape the storage directory. Authenticated users with RoleReader permissions or anonymous clients when publish authentication is disabled can read JSON files outside the attribute-view directory to disclose cross-scope database content.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/siyuan-note/siyuan/kernelGo | < 0.0.0-20260720151813-0f5a0e7c67b0 | 0.0.0-20260720151813-0f5a0e7c67b0 |
Affected products
2v3.7.3-beta.2, v3.7.3-beta.1, v3.7.0-rc.2, …+ 1 more
- (no CPE)range: v3.7.3-beta.2, v3.7.3-beta.1, v3.7.0-rc.2, …
- (no CPE)range: <3.7.3
Patches
Vulnerability mechanics
References
4News mentions
1- Siyuan Note: Eight Critical and High-Severity Vulnerabilities Disclosed TogetherVypr Intelligence · Aug 3, 2026