CVE-2026-100638
Last modified
CVE-2026-100638 is a high-severity vulnerability rated 7.6/10 on the CVSS scale. SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authenticated administrators to create arbitrary directory trees and write files outside the workspace boundary. Attackers can supply directory traversal sequences in the notebook parameter to escape the workspace data directory and write conf.json files to arbitrary locations accessible by the kernel process..
Description
SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authenticated administrators to create arbitrary directory trees and write files outside the workspace boundary. Attackers can supply directory traversal sequences in the notebook parameter to escape the workspace data directory and write conf.json files to arbitrary locations accessible by the kernel process.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-100638?
How severe is CVE-2026-100638?
How do I fix CVE-2026-100638?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-100632Parse Server is an open-source backend server. In versions >…6.5
- CVE-2026-100633SiYuan is a self-hosted personal knowledge management system…6.5
- CVE-2026-100634SiYuan before v3.8.4 does not validate the sender or restric…4.7
- CVE-2026-100635SiYuan before v3.8.4 contains an authentication bypass vulne…5.9
- CVE-2026-100636SiYuan versions before v3.8.4 contain a path traversal vulne…7.6
- CVE-2026-100637SiYuan versions before v3.8.4 contain a path traversal vulne…7.6
- CVE-2026-100639SiYuan v3.8.3 fails to HTML-escape the data-subtype attribut…8.8
- CVE-2026-10064A security flaw has been discovered in TRENDnet TEW-432BRP 3…9.8
- CVE-2026-100640SiYuan before v3.8.4 contains an authorization omission in t…4.7
- CVE-2026-100641SiYuan before v3.8.4 does not HTML-escape stored flashcard b…8
- CVE-2026-100642SiYuan versions from v2.1.0 before v3.8.4 contain a cross-si…7.6
- CVE-2026-100643SiYuan versions before v3.8.4 fail to properly escape four s…8
Are you affected by CVE-2026-100638?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
