<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T06:23:36.612135+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-335622</id>
    <title>EUVD-2026-335622</title>
    <updated>2026-10-06T06:23:36.672283+00:00</updated>
    <content>EUVD-2026-335622</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-335622"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59832</id>
    <title>fkie_cve-2026-59832</title>
    <updated>2026-10-06T06:23:36.672318+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler serveSnippets in kernel/server/serve.go joins a single-decoded request path with the snippets directory without subpath containment or sensitive-path checks, allowing an authenticated request such as /snippets/%2e%2e/%2e%2e/conf/conf.json to read workspace secrets and the document database. This issue is fixed in versions 3.7.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-59832"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-275h-v5h9-vr82</id>
    <title>GHSA-275h-v5h9-vr82 — Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyu…</title>
    <updated>2026-10-06T06:23:36.672352+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/siyuan-note/siyuan/kernel</p>
<p>Reporter: Cavan Loughran, Celvex Group Inc.</p>
<p>Summary
-------
The /snippets/*filepath route handler serveSnippets in kernel/server/serve.go performs a bare filepath.Join(util.SnippetsPath, filePath) on the single-decoded c.Request.URL.Path and serves the result with c.File(), with NO IsSubPath containment and NO IsSensitivePath denylist - unlike the sibling /export/ (serveExport) and /appearance/ (serveAppearance) handlers, which both carry IsSubPath, and unlike /assets/ (serveAssets), whose traversal was fixed in GHSA-p4m3-mgmm-c664. Because util.SnippetsPath = WorkspaceDir/data/snippets, an authenticated request to GET /snippets/%2e%2e/%2e%2e/conf/conf.json resolves to WorkspaceDir/conf/conf.json and leaks the kernel API token and AccessAuthCode (the same secret file CVE-2026-30869 leaked from /export/); GET /snippets/%2e%2e/%2e%2e/temp/siyuan.db leaks the full document database.</p>
<p>Affected versions
-----------------
v3.6.5 and current master (verified by direct source read). The /export/ and /assets/ fixes were endpoint-scoped and never reached serveSnippets.</p>
<p>Technical detail
----------------
Sink, kernel/server/serve.go, serveSnippets (verbatim, current master and v3.6.5):</p>
<p>func serveSnippets(ginServer *gin.Engine) {
      ginServer.Handle("GET", "/snippets/*filepath", model.CheckAuth, func(c *gin.Context) {
          filePath := strings.TrimPrefix(c.Request.URL.Path, "/snippets/")
          if !model.IsAdminRoleContext(c) {
              if "conf.json" == filePath {…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-275h-v5h9-vr82"/>
  </entry>
</feed>
