CVE-2026-73605: SiYuan before v3.7.4 Path Traversal via getUniqueFilename
SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that allows anonymous readers to probe filesystem existence without validation or confinement. Attackers can supply arbitrary absolute paths to determine whether files and directories exist on the host, enabling reconnaissance of the filesystem layout and installed software.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SiYuanto a version that resolves this vulnerability.Fixed in v3.7.4 - Compensating control
Restrict access to the SiYuan getUniqueFilename endpoint to authenticated/authorized users to prevent anonymous readers from probing filesystem existence (before v3.7.4).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73605?
The severity of CVE-2026-73605 is medium with a score of 5.8.
How do I fix CVE-2026-73605?
To fix CVE-2026-73605, you should upgrade to SiYuan version 3.7.4 or later.
What type of vulnerability is CVE-2026-73605?
CVE-2026-73605 is a path traversal vulnerability.
What can attackers do with CVE-2026-73605?
Attackers can exploit CVE-2026-73605 to probe filesystem existence by supplying arbitrary absolute paths.
In which software is CVE-2026-73605 found?
CVE-2026-73605 is found in SiYuan versions prior to 3.7.4.