UNKNOWNCVE-2026-33670
SiYuan has directory traversal within its publishing service
Platform
other
Component
siyuan
Fixed in
3.6.2
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to traverse and retrieve the file names of all documents under a notebook. Version 3.6.2 patches the issue.
How to fix
Actualice SiYuan a la versión 3.6.2 o superior. Esta versión corrige la vulnerabilidad de recorrido de directorios en el servicio de publicación.
Monitor your dependencies automatically
Get notified when new vulnerabilities affect your projects. Free forever.
Start free