Record summary

CVE-2026-33670 has a selected CVSS score of 9.8 (critical).

Description

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to traverse and retrieve the file names of all documents under a notebook. Version 3.6.2 patches the issue.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 30, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List< 3.6.2affected

github.com/siyuan-note/siyuan/kernel

Browse Go / github.com/siyuan-note/siyuan/kernel
GitHub AdvisoryThrough 0.0.0-20260317012524-fe4523fff2c8affected

References

3