S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jun 11, 2026

CVE-2026-33476 Scanner

CVE-2026-33476 Scanner - Path Traversal vulnerability in SiYuan

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.4k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-33476
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated file-serving endpoint under `/appearance/*filepath.` Due to improper path sanitization, attackers can perform directory traversal and read arbitrary files accessible to the server process. Authentication checks explicitly exclude this endpoint, allowing exploitation without valid credentials. Version 3.6.2 fixes this issue.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
siyuanby siyuan-note
< 3.6.2
Updated Aug 22, 2026View on NVD →
Detail

SiYuan is a personal knowledge management system used primarily by individuals and small organizations to effectively manage and access a wide array of information. It is designed to handle extensive documentation, personal notes, and collaborative features, making it widely deployed in educational, research, and professional environments. SiYuan is valued for its rich plugin ecosystem and customizable interface, allowing users to tailor the software to their specific knowledge management needs. It is usually installed on personal devices or hosted on servers for team access. Open-source by nature, SiYuan encourages community-driven development and adaptations catering to niche requirements. Emphasizing simplicity and efficiency, it has gained a substantial user base in various knowledge-centric domains.

The Path Traversal vulnerability in SiYuan allows attackers to exploit a file-serving endpoint without authorization. This allows unauthorized access to arbitrary files within the system directories. By bypassing authentication checks, the vulnerability exposes critical information stored on the server. Exploitation is done through crafted URLs, manipulating path navigation to traverse directories. As such, this flaw compels system administrators to secure file access and enforce strict path validations. The affected versions are highly susceptible until version 3.6.2, which patches this vital security lapse and strengthens the software's reliability against unauthorized access.

This vulnerability arises from improper input sanitization within the file-serving endpoint `/appearance/*filepath`. When exploited, it permits directory traversal using specially crafted file paths that navigate to system files outside the intended directory. The unprotected endpoint under the `/appearance` path grants file access regardless of authentication status, thus posing a significant risk for systems running vulnerable versions of SiYuan. Technical details showcase how attackers can send HTTP requests that exploit directory traversal to retrieve sensitive configurations. Effective mitigation requires updating to the secured version 3.6.2, which addresses the root cause by eliminating unauthorized access capabilities.

Exploiting the Path Traversal vulnerability enables attackers to access sensitive files that might contain confidential configurations or personal data. This unauthorized access can lead to data breaches, potentially leaking user credentials, sensitive documents, and proprietary information. By reading arbitrary files, attackers gain insights into user activity, system settings, and possibly even execute further attacks using the information captured. If not remediated, the vulnerability could facilitate extensive unauthorized surveillance and data theft scenarios, undermining user trust and system integrity.

REFERENCES

Solution Advice
  • Update SiYuan to version 3.6.2 or later to fix the directory traversal vulnerability.
  • Implement additional server-side input validation to ensure path traversal attempts are detected and blocked.
  • Regularly audit and monitor access logs to identify suspicious access patterns or unauthorized access attempts.
  • Deploy intrusion detection systems to alert on unexpected file access activities.
  • Enhance system permissions to ensure service accounts have the minimum necessary file access.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.