<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 12:10:54 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-291882</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-291882</link>
      <description>EUVD-2026-291882</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-291882</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40318</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40318</link>
      <description>&lt;p&gt;SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the user-controlled id parameter without validation or path boundary enforcement. An attacker can inject path traversal sequences such as ../ into the id value to escape the intended directory and delete arbitrary .json files on the server, including global configuration files and workspace metadata. This issue has been fixed in version 3.6.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the user-controlled id parameter without validation or path boundary enforcement. An attacker can inject path traversal sequences such as ../ into the id value to escape the intended directory and delete arbitrary .json files on the server, including global configuration files and workspace metadata. This issue has been fixed in version 3.6.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40318</guid>
    </item>
    <item>
      <title>GHSA-vw86-c94w-v3x4 — SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vw86-c94w-v3x4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The endpoint `/api/av/removeUnusedAttributeView` is vulnerable to a **path traversal (CWE-22)** that allows an attacker to delete arbitrary `.json` files on the server.&lt;/p&gt;
&lt;p&gt;The issue arises because user-controlled input (`id`) is directly used in filesystem path construction without validation or restriction.&lt;/p&gt;
&lt;p&gt;&amp;gt; Access to this endpoint (e.g., via a Reader-role or publish context) is considered a precondition and not part of the vulnerability. The root cause is unsafe path handling.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Steps To Reproduce&lt;/p&gt;
&lt;p&gt;1. Ensure the target instance has the publish service enabled (or any valid access to the endpoint).
2. Send the following request:&lt;/p&gt;
&lt;p&gt;```http
POST /api/av/removeUnusedAttributeView HTTP/1.1
Host: &amp;lt;target&amp;gt;
Content-Type: application/json&lt;/p&gt;
&lt;p&gt;{
  &amp;#34;id&amp;#34;: &amp;#34;../../../conf/conf&amp;#34;
}
```&lt;/p&gt;
&lt;p&gt;3. Observe that the request is accepted.
4. The server resolves the path outside the intended directory and deletes the target file.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker can delete arbitrary `.json` files within the workspace directory.&lt;/p&gt;
&lt;p&gt;This may lead to:&lt;/p&gt;
&lt;p&gt;* Deletion of global configuration files (e.g., `conf/conf.json`)
* Loss of user data and application state
* Corruption of workspace metadata
* Persistent application instability or forced recovery&lt;/p&gt;
&lt;p&gt;This represents a **server-side arbitrary file deletion primitive**, which can have severe impact depending on the targeted files.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;The vulnerable code constructs file paths as follows:&lt;/p&gt;
&lt;p&gt;```go
filepath.Join(util.DataDir, &amp;#34;st…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/siyuan-note/siyuan/kernel&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The endpoint `/api/av/removeUnusedAttributeView` is vulnerable to a **path traversal (CWE-22)** that allows an attacker to delete arbitrary `.json` files on the server.&lt;/p&gt;
&lt;p&gt;The issue arises because user-controlled input (`id`) is directly used in filesystem path construction without validation or restriction.&lt;/p&gt;
&lt;p&gt;&amp;gt; Access to this endpoint (e.g., via a Reader-role or publish context) is considered a precondition and not part of the vulnerability. The root cause is unsafe path handling.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Steps To Reproduce&lt;/p&gt;
&lt;p&gt;1. Ensure the target instance has the publish service enabled (or any valid access to the endpoint).
2. Send the following request:&lt;/p&gt;
&lt;p&gt;```http
POST /api/av/removeUnusedAttributeView HTTP/1.1
Host: &amp;lt;target&amp;gt;
Content-Type: application/json&lt;/p&gt;
&lt;p&gt;{
  &amp;#34;id&amp;#34;: &amp;#34;../../../conf/conf&amp;#34;
}
```&lt;/p&gt;
&lt;p&gt;3. Observe that the request is accepted.
4. The server resolves the path outside the intended directory and deletes the target file.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker can delete arbitrary `.json` files within the workspace directory.&lt;/p&gt;
&lt;p&gt;This may lead to:&lt;/p&gt;
&lt;p&gt;* Deletion of global configuration files (e.g., `conf/conf.json`)
* Loss of user data and application state
* Corruption of workspace metadata
* Persistent application instability or forced recovery&lt;/p&gt;
&lt;p&gt;This represents a **server-side arbitrary file deletion primitive**, which can have severe impact depending on the targeted files.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Technical Details&lt;/p&gt;
&lt;p&gt;The vulnerable code constructs file paths as follows:&lt;/p&gt;
&lt;p&gt;```go
filepath.Join(util.DataDir, &amp;#34;st…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vw86-c94w-v3x4</guid>
    </item>
  </channel>
</rss>
