S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jun 19, 2026

CVE-2026-54066 Scanner

CVE-2026-54066 Scanner - Path Traversal vulnerability in SiYuan

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.4k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-54066
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the patch for CVE-2026-41894 ("Path Traversal via Double URL Encoding") sanitized the /export/ route but the identical root cause remains in the /assets/*path route. In publish mode (anonymous read-only HTTP endpoint, default port 6808), an unauthenticated remote attacker can read arbitrary files inside WorkspaceDir — including conf/conf.json (which contains the AccessAuthCode SHA256 hash, API token, and sync keys), temp/siyuan.db, temp/blocktree.db, and siyuan.log — by double-URL-encoding .. segments. This vulnerability is fixed in 3.7.0.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
siyuanby siyuan-note
< 3.7.0
Updated Sep 9, 2026View on NVD →
Detail

SiYuan is a note-taking application widely used by individuals and organizations to organize and manage digital content efficiently. This software facilitates creating, organizing, and sharing notes, which is crucial for personal knowledge management, academic research, and collaborative work environments. SiYuan's intuitive interface and functionalities are designed to boost productivity, offering features that allow seamless integration with various digital tools and platforms. With its capability to sync across devices, SiYuan is popular among users who require portability and accessibility in managing their information repository. As digital collaboration increases, SiYuan's usage has expanded in both personal and professional domains to support knowledge sharing and organization. Ensuring the security of its users' data remains a priority, especially given the vast amount of sensitive information managed through the tool.

The detected vulnerability is a path traversal issue in SiYuan, specifically allowing unauthenticated access due to improper input validation in its URL handling. This vulnerability becomes significant as it permits unauthorized users to access sensitive files by maneuvering through the application's directory structure. The application fails to properly sanitize user inputs in the '/assets/' route, making it susceptible to path traversal attacks through double URL-encoding. Attackers exploit this weakness to gain unauthorized access to files that should be safeguarded, severely compromising data security protocols. Given that these attacks require no authentication, the risk escalates as more sensitive data can be exposed without user knowledge.

Technically, the vulnerability is exploited via a crafted URL that utilizes double URL-encoding to traverse directories. Attackers target the '/assets/' endpoint, which processes paths unsafely, leading to potential exposure of critical files such as 'conf/conf.json'. This JSON file contains pivotal information including API tokens and authentication codes, which are confidential. By manipulating the URL to bypass directory restrictions, attackers effectively access these files, gaining control over sensitive files in the WorkspaceDir. Through methods such as these, the application could be forced to inadvertently compromise API security, granting attackers unauthorized API access with valid credentials.

If exploited, this vulnerability could have severe impacts including unauthorized access to sensitive information stored within SiYuan notebooks. As critical API tokens and authentication credentials are disclosed through successful path traversal attacks, attackers can achieve full access to user data, potentially manipulating and extracting information without barriers. The risk of unauthorized script execution, document manipulation, and data theft drastically increases, raising alarm over privacy and data security standards. Given the application's role in managing personal and organizational knowledge, the implications of such access breaches are substantial, endangering user trust and system integrity.

REFERENCES

Solution Advice
  • Update SiYuan to version 3.7.0 or later to patch path traversal vulnerabilities.
  • Ensure input validation and sanitation to prevent unauthorized file path manipulation.
  • Regularly audit and patch dependencies to safeguard against similar vulnerabilities.
  • Implement application-layer controls to detect and log unauthorized access attempts.
  • Consider using a web application firewall (WAF) to protect against injection-type attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.