CVE-2026-40318: high-severity vulnerability in siyuan-note siyuan
SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.5epss 0.4%
exploitation probability
0.4%top 64% of all CVEs
observed exploitation
nono source reports it
SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the user-controlled id parameter without validation or path boundary enforcement. An attacker can inject path traversal sequences such as ../ into the id value to escape the intended directory and delete arbitrary .json files on the server, including global configuration files and workspace metadata. This issue has been fixed in version 3.6.4.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
Affected products
siyuan-note · siyuanRelated CVEs — siyuan-note siyuan
In the same product, most dangerous first.
CVE-2026-33476HIGHSiYuan has an Unauthenticated Arbitrary File Read via Path TraversalEPSS 3.1%CVE-2026-54066HIGHSiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read)EPSS 2.4%CVE-2026-69084CRITICALSiYuan before v3.7.3 SQL Injection via searchEmbedBlockEPSS 1.6%CVE-2026-69085CRITICALSiYuan before v3.7.3 SQL Injection via searchDocsEPSS 1.5%CVE-2026-34453HIGHSiYuan: Broken access control in /api/bookmark/getBookmark allows unauthenticated publish visitors to read password-protected bookmarked contentEPSS 1.5%CVE-2026-30869CRITICALSiYuan has a Path Traversal in /export Endpoint Allows Arbitrary File Read and Secret LeakageEPSS 1.2%