What is CVE-2026-69086?
A vulnerability in SiYuan versions before v3.7.3 fails to validate the 'avID' parameter in attribute-view read endpoints, enabling path traversal attacks that escape the storage directory. This affects authenticated users with RoleReader permissions or anonymous clients under certain publish authentication scenarios. Upgrading to version 3.7.3 or later is strongly recommended to mitigate the issue.
Azərbaycanca: SiYuan note-taking tətbiqinin v3.7.3-dən əvvəlki versiyalarında 'attribute-view read' endpoint-lərində 'avID' parametrinin düzgün yoxlanılmaması zəifliyi aşkarlanıb. Bu, autentifikasiya olunmuş 'RoleReader' icazəli istifadəçilərə və ya anonim müştərilərə kataloqdan kənara çıxan path traversal hücumları həyata keçirməyə imkan verir. Tətbiqi dərhal v3.7.3 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which endpoint does CVE-2026-69086 affect in the SiYuan application?
The vulnerability exists in the attribute-view read endpoints due to improper validation of the 'avID' parameter.
Who can exploit this path traversal attack?
Authenticated users with RoleReader permissions or anonymous clients under certain publish authentication scenarios can exploit it.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.