CRITICAL 9.4 NVD
CVE-2026-77086
SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform pat
SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequences. Attackers with admin access can write arbitrary files to any location via install operations or recursively delete directories via uninstall operations by supplying crafted packageName values.
References
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-wr4w-7vjm-mmx3
- https://www.vulncheck.com/advisories/siyuan-before-path-traversal-via-packagename
This critical severity vulnerability with a CVSS score of 9.4 was published on 2026-08-21 via NVD.
Risk Timeline
CVE Disclosed2026-08-21 · -1 days ago
Remediation Resources
vulnfeed aggregates 11625 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.