CVE-2026-40318
Last modified
CVE-2026-40318 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the user-controlled id parameter without validation or path boundary enforcement. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the user-controlled id parameter without validation or path boundary enforcement. An attacker can inject path traversal sequences such as ../ into the id value to escape the intended directory and delete arbitrary .json files on the server, including global configuration files and workspace metadata. This issue has been fixed in version 3.6.4.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| B3log | Siyuan | < 3.6.4 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-40318?
How severe is CVE-2026-40318?
How do I fix CVE-2026-40318?
Are you affected by CVE-2026-40318?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
