SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck endpoint that fails to validate the deckID parameter. An authenticated administrator can supply path traversal sequences to delete arbitrary .deck and .cards files outside the workspace directory.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 12:17
Updated : 2026-09-14 14:17
NVD link : CVE-2026-87815
Mitre link : CVE-2026-87815
CVE.ORG link : CVE-2026-87815
JSON object : View
Products Affected
No product.
CWE
CWE-73
External Control of File Name or Path
