SiYuan has an arbitrary file read and path traversal via /api/export/exportResources
Vulnerability Description
SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/exportResources endpoint is vulnerable to arbitary file read via path traversal. It is possible to manipulate the paths parameter to access and download arbitrary files from the host system by traversing the workspace directory structure. Version 3.1.16 contains a patch for the issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-55658
Credits & Attribution
No credits recorded in the NVD database.
References
More from siyuan-note
View All →Affected Vendor
siyuan-note
View all reports →