UNKNOWNCVE-2026-33670

SiYuan has directory traversal within its publishing service

Platform

other

Component

siyuan

Fixed in

3.6.2

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to traverse and retrieve the file names of all documents under a notebook. Version 3.6.2 patches the issue.

How to fix

Actualice SiYuan a la versión 3.6.2 o superior. Esta versión corrige la vulnerabilidad de recorrido de directorios en el servicio de publicación.

Monitor your dependencies automatically

Get notified when new vulnerabilities affect your projects. Free forever.

Start free