OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100637

HIGH · CVSS 7.6 EPSS 0.47% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Versions of SiYuan prior to 3.8.4 are vulnerable to a path traversal flaw in the checkoutRepo endpoint, enabling authenticated administrators to write JSON files outside designated workspace areas. This vulnerability allows attackers to exploit the sessionID parameter to overwrite arbitrary JSON files in writable directories, potentially compromising system integrity and data security. Organizations using affected SiYuan versions should prioritize immediate updates to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100637
Severity
HIGH
CVSS
7.6
EPSS
0.47%

Original NVD Description

SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authenticated administrators to write JSON files outside the workspace. Attackers can supply a sessionID parameter containing directory traversal sequences to overwrite arbitrary JSON files in pre-existing kernel-writable directories outside workspace boundaries.