CyberRota Analysis
AI-GeneratedVersions of SiYuan prior to v3.8.4 are vulnerable to a path traversal flaw in the exportBrowserHTML endpoint, allowing authenticated administrators to write arbitrary HTML content to the index.html file outside the designated workspace directory. This vulnerability can be exploited to overwrite index.html in any writable location, leading to potential stored XSS attacks or workspace defacement. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SiYuan versions before v3.8.4 contain a path traversal vulnerability in the exportBrowserHTML endpoint that allows authenticated administrators to write arbitrary HTML content to index.html outside the workspace directory. Attackers can supply a folder parameter with directory traversal sequences to escape the export directory and overwrite index.html in any pre-existing kernel-writable location, enabling stored XSS or workspace defacement.