{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/siyuan--2.1.0--3.8.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:siyuan:siyuan:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.6,"id":"CVE-2026-100636"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SiYuan (\u003c 3.8.4)","SiYuan (\u003e= 2.1.0, \u003c 3.8.4)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","xss","rce","electron"],"_cs_type":"advisory","_cs_vendors":["SiYuan"],"content_html":"\u003cp\u003eSiYuan versions prior to v3.8.4 contain a critical path traversal vulnerability in the exportBrowserHTML endpoint. This flaw allows an authenticated administrator to manipulate the folder parameter by including directory traversal sequences. By successfully exploiting this, an attacker can escape the restricted export directory and overwrite the index.html file in any location that the application kernel has write permissions to. This vulnerability poses a significant risk for stored Cross-Site Scripting (XSS) attacks or workspace defacement, as it allows the injection of arbitrary HTML content into the application environment. Defenders should prioritize updating to SiYuan v3.8.4 or later to mitigate this risk.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows authenticated administrators to perform arbitrary file writes, leading to potential stored XSS or full application-level defacement. If compromised, an attacker could inject malicious scripts into the index.html file, which would then be executed in the context of other users or administrators accessing the application, facilitating further account takeover or malicious redirections.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all SiYuan installations to version v3.8.4 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit web server logs for suspicious POST requests to the exportBrowserHTML endpoint containing path traversal characters like '../' or '..%2f'.\u003c/li\u003e\n\u003cli\u003eRestrict administrative access to the SiYuan interface to trusted personnel to limit the attack surface for this authenticated vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-26T15:06:01Z","date_published":"2026-09-26T15:03:37Z","id":"https://feed.craftedsignal.io/briefs/2026-09-siyuan-path-traversal/","summary":"SiYuan versions prior to v3.8.4 are vulnerable to a path traversal attack via the exportBrowserHTML endpoint, allowing authenticated administrators to overwrite arbitrary index.html files.","title":"Path Traversal in SiYuan Export Functionality","url":"https://feed.craftedsignal.io/briefs/2026-09-siyuan-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - SiYuan (\u003e= 2.1.0, \u003c 3.8.4)","version":"https://jsonfeed.org/version/1.1"}