CVE-2026-87815

SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck endpoint that fails to validate the deckID parameter. An authenticated administrator can supply path traversal sequences to delete arbitrary .deck and .cards files outside the workspace directory.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 12:17

Updated : 2026-09-14 14:17


NVD link : CVE-2026-87815

Mitre link : CVE-2026-87815

CVE.ORG link : CVE-2026-87815


JSON object : View

Products Affected

No product.

CWE
CWE-73

External Control of File Name or Path