CRITICAL 9.4 NVD

CVE-2026-77086

SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform pat

SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequences. Attackers with admin access can write arbitrary files to any location via install operations or recursively delete directories via uninstall operations by supplying crafted packageName values.

References

Published: 2026-08-21 · Source: NVD · Feed updated: 2026-08-21
This critical severity vulnerability with a CVSS score of 9.4 was published on 2026-08-21 via NVD.

Risk Timeline

CVE Disclosed2026-08-21 · -1 days ago

Remediation Resources

vulnfeed aggregates 11625 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.