Impact
A path‑traversal flaw in the file-read endpoint of SiYuan causes the application to follow symbolic links when opening requested assets under data/assets/. Attackers with the reader role can therefore request a logical asset that is a symlink to any file outside the workspace and receive the contents of that file. The primary consequence is a breach of confidentiality as sensitive files may be revealed to an authenticated attacker.
Affected Systems
SiYuan by Siyuan Note, versions prior to 3.8.2, are affected. All releases before the 3.8.2 update expose the file‑read endpoint to this vulnerability, allowing any user granted reader role to exploit it.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderately high severity. The exploit requires the attacker to have a reader role, which is often granted to regular users or may be obtained through credential compromise or social engineering. No publicly available exploit has been reported and the EPSS score is not available, but the vulnerability is not listed in CISA’s KEV catalog. Given the ease of exploitation once an attacker has reader access, the risk to affected organizations is significant and should be mitigated promptly.
OpenCVE Enrichment