Impact
SiYuan versions prior to 3.7.4 expose an endpoint that accepts a file path without validation and passes it to the OS remove function, allowing an attacker to delete any file or directory the process can reach. The impact is the loss of critical data, configuration files, or system components, potentially leading to a complete compromise of application integrity.
Affected Systems
The affected product is SiYuan Note (siyuan), specifically all releases before v3.7.4, on any platform where the server process runs.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity, and while the EPSS score is not available, the lack of KEV listing suggests limited widespread exploitation evidence. The flaw requires authenticated administrator privileges and a path to the target, so the attack vector is internal through legitimate admin accounts. Successful exploitation results in arbitrary file deletion anywhere the server process can write.
OpenCVE Enrichment