Impact
SiYuan versions preceding v3.8.2 contain a path traversal flaw in the /api/riff/removeRiffDeck endpoint that does not properly validate the deckID parameter. An authenticated administrator can supply directory traversal sequences to delete arbitrary .deck and .cards files that reside outside the normal workspace directory. The vulnerability allows the removal of critical user data but does not provide direct code execution or arbitrary file read capabilities. The primary security consequence is the loss of important documents and potential disruption of workflow for authorized users.
Affected Systems
The flaw affects all releases of the SiYuan note application before version 3.8.2 from the vendor siyuan-note. Users deploying earlier builds are susceptible, regardless of operating system or deployment context.
Risk and Exploitability
The CVSS score of 8.4 places the issue in the High severity range, and the vulnerability requires an attacker to have administrative privileges to trigger the file deletion exploit. Because the flaw is triggered via a legitimate API endpoint used by administrators, the attack vector is likely internal or from a compromised administrator account. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, yet the potential for damaging data loss remains significant for systems accessible to admin users.
OpenCVE Enrichment