CVE-2026-100638
7.6 HIGHpublic exploit availablePublished 2026-09-26 · Updated 2026-09-26
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authenticated administrators to create arbitrary directory trees and write files outside the workspace boundary. Attackers can supply directory traversal sequences in the notebook parameter to escape the workspace data directory and write conf.json files to arbitrary locations accessible by the kernel process.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:L
Weaknesses
CWE-73
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-100637PoC
- UNSCOREDCVE-2026-101126
- HIGHCVE-2026-13248
- HIGHCVE-2026-15307PoC
- HIGHCVE-2026-18806
- MEDIUMCVE-2026-19860
- HIGHCVE-2026-53940PoC
- UNSCOREDCVE-2026-54582PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.