What is CVE-2026-74798?
CVE-2026-74798 is a path traversal vulnerability in the 'database_clean' MCP tool of SiYuan kernel prior to version 3.7.4. The vulnerability arises from insufficient validation of the 'id' parameter, which is used to construct filesystem paths, potentially allowing unauthorized access. Upgrading SiYuan kernel to version 3.7.4 or later is recommended.
Azərbaycanca: CVE-2026-74798 SiYuan kernel-in v3.7.4-dən əvvəlki versiyalarında 'database_clean' MCP alətində path traversal zəifliyidir. Bu zəiflik 'id' parametrinin düzgün yoxlanılmaması səbəbindən baş verir və təcavüzkara fayl sisteminə icazəsiz giriş imkanı yarada bilər. SiYuan kernel-i ən azı v3.7.4 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of SiYuan kernel are affected by the CVE-2026-74798 path traversal vulnerability?
Versions prior to v3.7.4 are affected.
What is the recommended mitigation for CVE-2026-74798?
Upgrading SiYuan kernel to at least version 3.7.4 is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.