What is CVE-2026-73605?
SiYuan versions prior to 3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint, allowing anonymous readers to probe filesystem existence without validation. The flaw permits attackers to supply arbitrary absolute paths to determine file and directory presence. Users should immediately upgrade to SiYuan version 3.7.4 or later to mitigate the risk.
Azərbaycanca: SiYuan qeydiyyat tətbiqinin 3.7.4 versiyasından əvvəlki versiyalarında "getUniqueFilename" endpoint-də path traversal zəifliyi aşkarlanıb. Bu boşluq anonim oxuculara fayl sistemi mövcudluğunu yoxlamağa imkan verir. Təhlükəsizlik üçün dərhal SiYuan-ı ən az 3.7.4 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of SiYuan are affected by CVE-2026-73605?
This path traversal vulnerability affects all SiYuan versions prior to 3.7.4.
What does CVE-2026-73605 allow anonymous users to do?
The vulnerability allows anonymous readers to probe filesystem existence.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.