Ad

CVE-2026-32749

CRITICAL CVSS 3.1: 9.1 EPSS 0.09%
Updated Mar 23, 2026
B3Log
Parameter Value
CVSS 9.1 (CRITICAL)
Affected Versions before 3.6.1
Fixed In 3.6.1
Type CWE-22 (Path Traversal), CWE-73 (External Control of File Name or Path)
Vendor B3Log
Public PoC No

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importSY and POST /api/import/importZipMd write uploaded archives to a path derived from the multipart filename field without sanitization, allowing an admin to write files to arbitrary locations outside the temp directory - including system paths that enable RCE. This can lead to aata destruction by overwriting workspace or application files, and for Docker containers running as root (common default), this grants full container compromise.

This issue has been fixed in version 3.6.1.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
High
Admin privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
B3log Siyuan
cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*
3.6.1