8.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
Description
SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the user-controlled id parameter without validation or path boundary enforcement. An attacker can inject path traversal sequences such as ../ into the id value to escape the intended directory and delete arbitrary .json files on the server, including global configuration files and workspace metadata. This issue has been fixed in version 3.6.4.
AI Analysis
Path traversal vulnerability in SiYuan's /api/av/removeUnusedAttributeView endpoint, allowing deletion of arbitrary .json files on the server.
Basic Information
ID
CVE-2026-40318
Source
GitHub_M
Published
Apr 16, 2026 at 22:54
Affected Product
Vendor
siyuan-note
Product
siyuan
Version
< 3.6.4
Affected Versions
siyuan-note siyuan < 3.6.4
CWE Classification
AI Assessment
AI Score
8.5 / 10
AI Severity
High
Vendor
siyuan-note
Product
SiYuan
Version
3.6.3 and prior