LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-33476

b3log · siyuan

Published
CVSS7.5
Severityhigh
WeaknessCWE-22
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated file-serving endpoint under `/appearance/*filepath.` Due to improper path sanitization, attackers can perform directory traversal and read arbitrary files accessible to the server process. Authentication checks explicitly exclude this endpoint, allowing exploitation without valid credentials. Version 3.6.2 fixes this issue.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-33476

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-33476.