github.com
https://github.com/siyuan-note/siyuan CVE-2026-33670
CRITICAL
SiYuan has directory traversal within its publishing service
Record summary
CVE-2026-33670 has a selected CVSS score of 9.8 (critical).
Description
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to traverse and retrieve the file names of all documents under a notebook. Version 3.6.2 patches the issue.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 30, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | < 3.6.2 | affected | |
github.com/siyuan-note/siyuan/kernelBrowse Go / github.com/siyuan-note/siyuan/kernel | GitHub Advisory | Through 0.0.0-20260317012524-fe4523fff2c8 | affected |
References
3github.comConfirmation
https://github.com/siyuan-note/siyuan/security/advisories/GHSA-xmw9-6r43-x9ww nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-33670