MEDIUM 5.8 GitHub

CVE-2026-73605

SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesy

### Summary `/api/file/getUniqueFilename` takes a path from the request body and passes it to a filesystem existence check with no validation, confinement or authorization. The response distinguishes paths that exist from paths that do not, so an anonymous reader in publish mode can probe arbitrary locations on the host, one request per probe. Files and directories both work. Every neighbouring file route either requires an administrator or confines the path first. ### Details **Route.** `ke

Affected Products

References

Published: 2026-10-01 · Source: GitHub · Feed updated: 2026-10-01
This medium severity vulnerability with a CVSS score of 5.8 was published on 2026-10-01 via GitHub. Affected: go/github.com/siyuan-note/siyuan/kernel < 0.0.0-20260812083335-251596fc0de2.
vulnfeed aggregates 9446 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.