Impact
SiYuan versions before 3.8.4 contain a path traversal flaw in the checkoutRepo endpoint that allows authenticated administrators to supply a sessionID parameter with directory traversal sequences. This flaw lets an attacker write or overwrite JSON files outside the intended workspace boundaries. Modifying or replacing arbitrary JSON files can lead to unintended behavior or exploitation of downstream processes that consume these files, potentially escalating to code execution or system compromise.
Affected Systems
The affected product is Siyuan Note, all releases before v3.8.4. The vendor is siyuan-note, product name Siyuan. No further version granularity is disclosed in the advisory.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity vulnerability. EPSS is not available, and the issue is not listed in CISA KEV. The attack requires an authenticated administrator session, but the payload can be crafted by an attacker with such access. Because the flaw permits writing to kernel‑writable directories, exploitation could provide elevated privileges or persistence if the target files are trusted by the operating system or other applications.
OpenCVE Enrichment