CVE-2026-69086: SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers to construct traversal paths that escape
SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers to construct traversal paths that escape the storage directory. Authenticated users with RoleReader permissions or anonymous clients when publish authentication is disabled can read JSON files outside the attribute-view directory to disclose cross-scope database content.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-69086
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-69086 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for SiYuan
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalCVE-2026-69085: SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs en…nvd · 2026-08-03
- criticalCVE-2026-69084: SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a cli…nvd · 2026-08-03
- criticalCVE-2026-69083: SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAsset…nvd · 2026-08-03
- highCVE-2026-68587: SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadin…nvd · 2026-08-03
- highCVE-2026-68586: SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackme…nvd · 2026-08-03
- mediumCVE-2026-68585: SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/ge…nvd · 2026-08-03
More from NVD Recent CVEs
- mediumCVE-2026-8508: An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S…2026-08-04
- highCVE-2026-6837: A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel …2026-08-04
- mediumCVE-2026-18720: A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown co…2026-08-04
- mediumCVE-2026-17614: A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileReposito…2026-08-04
- mediumCVE-2026-18719: A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the fil…2026-08-04