High severity8.7NVD Advisory· Published Sep 9, 2026
CVE-2026-87815
CVE-2026-87815
Description
SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck endpoint that fails to validate the deckID parameter. An authenticated administrator can supply path traversal sequences to delete arbitrary .deck and .cards files outside the workspace directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<3.8.2+ 1 more
- (no CPE)range: <3.8.2
- (no CPE)range: <3.8.2
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.