CVE-2026-100637

Summary

SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authenticated administrators to write JSON files outside the workspace. Attackers can supply a sessionID parameter containing directory traversal sequences to overwrite arbitrary JSON files in pre-existing kernel-writable directories outside workspace boundaries.

Affected Software

VendorProductVersion RangeStatus
siyuan-notesiyuan0 < 3.8.4affected
siyuan-notesiyuan3.8.4unaffected

Weaknesses

  • CWE-73: External Control of File Name or Path

References