Impact
SiYuan versions prior to 3.8.1 contain a path traversal flaw in the RenderTemplate function, accessed via the POST /api/template/render endpoint. The vulnerability allows an authenticated attacker to reference arbitrary files within the workspace directory, bypassing the intended restriction by lacking a sensitive‑path exclusion. This provides the attacker with the ability to read sensitive files, such as conf/conf.json, which stores the API token and cookie signing key, thereby compromising confidentiality. The weakness is classified as CWE‑668 (Security Misconfiguration).
Affected Systems
The flaw affects all releases of SiYuan before 3.8.1, including 3.8.0 and earlier. End users must be using the open‑source note‑taking application from the vendor siyuan‑note. No specific patch versions beyond 3.8.0 are reported as vulnerable, but the fix was introduced in 3.8.1.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated session, so internal users or attackers who have compromised authentication credentials could target the API. Because EPSS is not available, the actual likelihood of exploitation cannot be quantified, but the presence of a path traversal flaw has been demonstrated in a public advisory, suggesting the problem remains open until a patch is applied.
OpenCVE Enrichment