CVE-2026-32749

HIGH

SiYuan importSY/importZipMd: Path Traversal via multipart filename enables arbitrary file write

Title source: cna
STIX 2.1

Description

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importSY and POST /api/import/importZipMd write uploaded archives to a path derived from the multipart filename field without sanitization, allowing an admin to write files to arbitrary locations outside the temp directory - including system paths that enable RCE. This can lead to aata destruction by overwriting workspace or application files, and for Docker containers running as root (common default), this grants full container compromise. This issue has been fixed in version 3.6.1.

Scores

CVSS v3 7.6
EPSS 0.0012
EPSS Percentile 30.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22 CWE-73
Status published
Products (2)
siyuan-note/siyuan 0Go
siyuan-note/siyuan < 3.6.1
Published Mar 19, 2026
Tracked Since Mar 20, 2026