CVE-2026-73605
published 2026-08-13CVE-2026-73605: SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that allows anonymous readers to probe filesystem…
PriorityP335medium5.8CVSS 3.1
AVNACLPRNUINSCCLINAN
EPSS
0.19%
9.4th percentile
SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that allows anonymous readers to probe filesystem existence without validation or confinement. Attackers can supply arbitrary absolute paths to determine whether files and directories exist on the host, enabling reconnaissance of the filesystem layout and installed software.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siyuan-note | siyuan | < 3.7.4 | 3.7.4 |
CVSS provenance
nvdv3.15.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
siyuan-note SiYuan up to 3.7.3 getUniqueFilename endpoint path traversal (CNNVD-2026-98198888)
vuldb·2026-08-15·CVSS 5.8
CVE-2026-73605 [MEDIUM] siyuan-note SiYuan up to 3.7.3 getUniqueFilename endpoint path traversal (CNNVD-2026-98198888)
A vulnerability was found in siyuan-note SiYuan up to 3.7.3. It has been classified as problematic. This impacts an unknown function of the component getUniqueFilename endpoint. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2026-73605. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
GHSA
SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that allows anonymous readers to probe filesystem existence without validation or confinement.
ghsa_unreviewed·2026-08-13
CVE-2026-73605 [MEDIUM] CWE-862 SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that allows anonymous readers to probe filesystem existence without validation or confinement.
SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that allows anonymous readers to probe filesystem existence without validation or confinement. Attackers can supply arbitrary absolute paths to determine whether files and directories exist on the host, enabling reconnaissance of the filesystem layout and installed software.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-13
Published