CVE-2026-40318
SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the user-controlled id parameter without validation or path boundary enforcement. An attacker can inject path traversal sequences such as ../ into the id value to escape the intended directory and delete arbitrary .json files on the server, including global configuration files and workspace metadata. This issue has been fixed in version 3.6.4.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
- EPSS probability
- 0.29%
- CWE
- CWE-24
- Published
- 2026-04-16
- Last modified
- 2026-04-18
Affected products
- siyuan-note siyuan
Weakness type
Related vulnerabilities
- CVE-2026-14947 — Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Remote Code Execution via malicious ZIP file
- CVE-2026-76353 — Path Traversal through Knowledge Bundle Replication in Splunk Enterprise
- CVE-2026-73573 — In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra...
- CVE-2026-48047 — XWiki Platform vulnerable to potential arbitrary file writing using path traversal from (subwiki) admin
- CVE-2026-66140 — Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and...
- CVE-2026-46687 — Emlog Local File Inclusion (LFI)
- CVE-2026-44942 — libzypp .repo files can have an optional path which can lead to path traversal attacks
- CVE-2026-49103 — Webmin before 2.640 does not safely construct a filename for saving of an attachment within the...