<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T01:03:10.981062+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-291882</id>
    <title>EUVD-2026-291882</title>
    <updated>2026-10-06T01:03:11.037351+00:00</updated>
    <content>EUVD-2026-291882</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-291882"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40318</id>
    <title>fkie_cve-2026-40318</title>
    <updated>2026-10-06T01:03:11.037391+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the user-controlled id parameter without validation or path boundary enforcement. An attacker can inject path traversal sequences such as ../ into the id value to escape the intended directory and delete arbitrary .json files on the server, including global configuration files and workspace metadata. This issue has been fixed in version 3.6.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40318"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vw86-c94w-v3x4</id>
    <title>GHSA-vw86-c94w-v3x4 — SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`</title>
    <updated>2026-10-06T01:03:11.037426+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/siyuan-note/siyuan/kernel</p>
<p>## Summary</p>
<p>The endpoint `/api/av/removeUnusedAttributeView` is vulnerable to a **path traversal (CWE-22)** that allows an attacker to delete arbitrary `.json` files on the server.</p>
<p>The issue arises because user-controlled input (`id`) is directly used in filesystem path construction without validation or restriction.</p>
<p>&gt; Access to this endpoint (e.g., via a Reader-role or publish context) is considered a precondition and not part of the vulnerability. The root cause is unsafe path handling.</p>
<p>---</p>
<p>## Steps To Reproduce</p>
<p>1. Ensure the target instance has the publish service enabled (or any valid access to the endpoint).
2. Send the following request:</p>
<p>```http
POST /api/av/removeUnusedAttributeView HTTP/1.1
Host: &lt;target&gt;
Content-Type: application/json</p>
<p>{
  "id": "../../../conf/conf"
}
```</p>
<p>3. Observe that the request is accepted.
4. The server resolves the path outside the intended directory and deletes the target file.</p>
<p>---</p>
<p>## Impact</p>
<p>An attacker can delete arbitrary `.json` files within the workspace directory.</p>
<p>This may lead to:</p>
<p>* Deletion of global configuration files (e.g., `conf/conf.json`)
* Loss of user data and application state
* Corruption of workspace metadata
* Persistent application instability or forced recovery</p>
<p>This represents a **server-side arbitrary file deletion primitive**, which can have severe impact depending on the targeted files.</p>
<p>---</p>
<p>## Technical Details</p>
<p>The vulnerable code constructs file paths as follows:</p>
<p>```go
filepath.Join(util.DataDir, "st…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vw86-c94w-v3x4"/>
  </entry>
</feed>
