CVE-2026-100637
7.6 HIGHpublic exploit availablePublished 2026-09-26 · Updated 2026-09-26
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authenticated administrators to write JSON files outside the workspace. Attackers can supply a sessionID parameter containing directory traversal sequences to overwrite arbitrary JSON files in pre-existing kernel-writable directories outside workspace boundaries.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:L
Weaknesses
CWE-73
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-100638PoC
- UNSCOREDCVE-2026-101126
- HIGHCVE-2026-13248
- HIGHCVE-2026-15307PoC
- HIGHCVE-2026-18806
- MEDIUMCVE-2026-19860
- HIGHCVE-2026-53940PoC
- UNSCOREDCVE-2026-54582PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.