CVE-2026-73605: CVE-2026-73605: Path Traversal and File Existence Oracle via getUniqueFilename Endpoint in SiYuan
CVE-2026-73605: Path Traversal and File Existence Oracle via getUniqueFilename Endpoint in SiYuan Vulnerability ID: CVE-2026-73605 CVSS Score: 6.9 Published: 2026-10-01 An authorization bypass and path traversal vul
CVE-2026-73605: Path Traversal and File Existence Oracle via getUniqueFilename Endpoint in SiYuan
Vulnerability ID: CVE-2026-73605
CVSS Score: 6.9
Published: 2026-10-01
An authorization bypass and path traversal vulnerability exists in the SiYuan knowledge workspace platform. The vulnerability is located in the '/api/file/getUniqueFilename' endpoint inside the 'github.com/siyuan-note/siyuan/kernel' package. Under default configurations, this route is exposed to users who satisfy basic authentication middleware checks, which includes anonymous readers in publish mode. By supplying unvalidated absolute paths, remote attackers can verify the existence of files and directories across the host operating system, establishing a high-fidelity file existence oracle.
TL;DR
Unauthenticated remote users can verify the existence of files and folders on the host operating system by sending crafted path parameters to the SiYuan file utility endpoint, leading to sensitive host system information disclosure.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-862
- Attack Vector: Network (AV:N)
- CVSS v4.0 Base Score: 6.9
- EPSS Score: 0.00325 (Percentile: 23.19%)
- Impact: Filesystem structure reconnaissance
- Exploit Status: Proof-of-Concept Available
- KEV Status: Not Listed
Affected Systems
- SiYuan personal knowledge management system
-
SiYuan: < 3.7.4 (Fixed in:
3.7.4)
Exploit Details
- GitHub Security Advisory: Exploit methodology and vulnerability overview documented in the official advisory.
Mitigation Strategies
- Upgrade SiYuan to version v3.7.4 or later
- Restrict access to the SiYuan API via network access control lists
- Disable anonymous publish mode if not strictly required
Remediation Steps:
- Identify all active instances of SiYuan running versions prior to v3.7.4
- Apply the v3.7.4 update from the official source
- Verify that the /api/file/getUniqueFilename endpoint no longer accepts absolute paths outside the workspace
References
- NVD - CVE-2026-73605
- CVE.org - CVE-2026-73605
- GitHub Security Advisory GHSA-hf8h-97gm-4x2p
- VulnCheck Advisory Portal
- SiYuan Repository
Read the full report for CVE-2026-73605 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.