CVE-2026-100636 HIGH
← Quay lại danh sách
Dịch vụ / phần mềm liên quan:
Chưa phân loại — không khớp danh sách dịch vụ/phần mềm đang theo dõi (xem/thêm ở
internal/cve/categories.go), hoặc NVD chưa cung cấp đủ dữ liệu vendor/sản phẩm cho CVE này.
Mô tả
SiYuan versions before v3.8.4 contain a path traversal vulnerability in the exportBrowserHTML endpoint that allows authenticated administrators to write arbitrary HTML content to index.html outside the workspace directory. Attackers can supply a folder parameter with directory traversal sequences to escape the export directory and overwrite index.html in any pre-existing kernel-writable location, enabling stored XSS or workspace defacement.
Chi tiết
| Trạng thái | Deferred |
| Điểm CVSS | 7.6 (v3.1) |
| Vector CVSS | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:L |
| Ngày công bố | 21:16 26/09/2026 |
| Ngày cập nhật | 00:17 29/09/2026 |
| Nguồn dữ liệu | nvd |
CWE
Sản phẩm bị ảnh hưởng
Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.
Tài liệu tham khảo
- [disclosure@vulncheck.com] https://github.com/siyuan-note/siyuan/security/advisories/GHSA-jf98-m24w-gm9m
- [disclosure@vulncheck.com] https://www.vulncheck.com/advisories/siyuan-before-3.8.4-path-traversal-via-exportbrowserhtml-folder
- [134c704f-9b21-4f2e-91b3-4a467353bcc0] https://github.com/siyuan-note/siyuan/security/advisories/GHSA-jf98-m24w-gm9m
Lịch sử thay đổi
| Thời gian | Loại | Trường | Giá trị cũ | Giá trị mới |
|---|---|---|---|---|
| 00:27 29/09/2026 | CREATED | cve | HIGH |