CyberRota Analysis
AI-GeneratedVersions of SiYuan prior to 3.8.4 are vulnerable to a path traversal flaw in the checkoutRepo endpoint, enabling authenticated administrators to write JSON files outside designated workspace areas. This vulnerability allows attackers to exploit the sessionID parameter to overwrite arbitrary JSON files in writable directories, potentially compromising system integrity and data security. Organizations using affected SiYuan versions should prioritize immediate updates to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SiYuan versions before v3.8.4 contain a path traversal vulnerability in the checkoutRepo endpoint that allows authenticated administrators to write JSON files outside the workspace. Attackers can supply a sessionID parameter containing directory traversal sequences to overwrite arbitrary JSON files in pre-existing kernel-writable directories outside workspace boundaries.