CVE-2026-33476

HIGH NUCLEI

SiYuan <3.6.2 appearance Filepath - Arbitrary File Read

Title source: manual
STIX 2.1

Exploitation Summary

CVE-2026-33476 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated file-serving endpoint under `/appearance/*filepath.` Due to improper path sanitization, attackers can perform directory traversal and read arbitrary files accessible to the server process. Authentication checks explicitly exclude this endpoint, allowing exploitation without valid credentials. Version 3.6.2 fixes this issue.

Nuclei Templates (1)

SiYuan <= v3.6.1 - Path Traversal
HIGHVERIFIEDby WRG-11
Shodan: http.favicon.hash:-1450125239

Scores

CVSS v3 7.5
EPSS 0.0333
EPSS Percentile 87.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22 CWE-73
Status published
Products (3)
b3log/siyuan < 3.6.2
siyuan-note/siyuan 0Go
siyuan-note/siyuan < 3.6.2
Published Mar 20, 2026
Tracked Since Mar 21, 2026