DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-73605: CVE-2026-73605: Path Traversal and File Existence Oracle via getUniqueFilename Endpoint in SiYuan

CVE-2026-73605: Path Traversal and File Existence Oracle via getUniqueFilename Endpoint in SiYuan

Vulnerability ID: CVE-2026-73605
CVSS Score: 6.9
Published: 2026-10-01

An authorization bypass and path traversal vulnerability exists in the SiYuan knowledge workspace platform. The vulnerability is located in the '/api/file/getUniqueFilename' endpoint inside the 'github.com/siyuan-note/siyuan/kernel' package. Under default configurations, this route is exposed to users who satisfy basic authentication middleware checks, which includes anonymous readers in publish mode. By supplying unvalidated absolute paths, remote attackers can verify the existence of files and directories across the host operating system, establishing a high-fidelity file existence oracle.

TL;DR

Unauthenticated remote users can verify the existence of files and folders on the host operating system by sending crafted path parameters to the SiYuan file utility endpoint, leading to sensitive host system information disclosure.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-862
  • Attack Vector: Network (AV:N)
  • CVSS v4.0 Base Score: 6.9
  • EPSS Score: 0.00325 (Percentile: 23.19%)
  • Impact: Filesystem structure reconnaissance
  • Exploit Status: Proof-of-Concept Available
  • KEV Status: Not Listed

Affected Systems

  • SiYuan personal knowledge management system
  • SiYuan: < 3.7.4 (Fixed in: 3.7.4)

Exploit Details

Mitigation Strategies

  • Upgrade SiYuan to version v3.7.4 or later
  • Restrict access to the SiYuan API via network access control lists
  • Disable anonymous publish mode if not strictly required

Remediation Steps:

  1. Identify all active instances of SiYuan running versions prior to v3.7.4
  2. Apply the v3.7.4 update from the official source
  3. Verify that the /api/file/getUniqueFilename endpoint no longer accepts absolute paths outside the workspace

References


Read the full report for CVE-2026-73605 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)