CVE-2026-33476: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-33476 is an unauthenticated arbitrary file read vulnerability in SiYuan, a self-hosted personal knowledge management application, caused by improper path sanitization (path traversal). It affects all versions up to and including v3.6.1, and was patched in v3.6.2. The vulnerability was published on March 20, 2026, with a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Security Advisory).

Technical details

The root cause is a combination of CWE-22 (Path Traversal) and CWE-73 (External Control of File Name or Path) in kernel/server/serve.go. The /appearance/*filepath endpoint constructs a filesystem path using filepath.Join(appearancePath, strings.TrimPrefix(c.Request.URL.Path, "/appearance/")) without sanitizing or normalizing the user-supplied path component, allowing ../ sequences to escape the intended appearancePath directory. Critically, the authentication middleware in session.go explicitly skips authentication for any request prefixed with /appearance/, meaning no credentials are required to exploit this endpoint. The resolved path is then served directly via c.File(filePath) without any boundary verification (Security Advisory, Patch Commit).

Impact

Successful exploitation allows an unauthenticated remote attacker to read any file accessible to the SiYuan server process, including workspace configuration files, user notes and stored data, API tokens and secrets, and local system files depending on OS-level permissions. This can lead to sensitive information disclosure, credential leakage, and further system compromise through exposed secrets. There is no integrity or availability impact, but the confidentiality impact is rated High (Security Advisory).

Exploitability

A public proof-of-concept (PoC) exploit is available in the GitHub security advisory, consisting of a simple curl command requiring no authentication or special tooling. No credentials or prior access are required, and attack complexity is low. The EPSS score is approximately 0.352% (58th percentile), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing. A Nuclei template for automated detection was also added to the ProjectDiscovery nuclei-templates repository (GitHub Advisory, Security Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible SiYuan instances (default port 6806) using tools like Shodan, Censys, or by scanning internal networks. Confirm the service is running by accessing http://<target>:6806.
  2. Identify vulnerable version: Confirm the target is running SiYuan v3.6.1 or earlier, as versions v3.6.2+ include the path traversal fix.
  3. Craft traversal request: Construct a URL with directory traversal sequences targeting the unauthenticated /appearance/ endpoint, e.g., http://<target>:6806/appearance/../../data/conf.json to read the workspace configuration file.
  4. Send request with path-as-is flag: Use curl with the --path-as-is flag to prevent the HTTP client from normalizing the ../ sequences before sending:
    curl -v --path-as-is "http://<target>:6806/appearance/../../data/conf.json"
  5. Read arbitrary files: Adjust the traversal depth and target path to read other sensitive files such as API tokens, user notes, or OS-level files (e.g., /etc/passwd on Linux) based on the server process permissions.
  6. Leverage exposed secrets: Use any extracted API tokens, credentials, or configuration data to escalate access or pivot to other systems (Security Advisory).

Indicators of compromise

  • Network: Unusual HTTP GET requests to the SiYuan service (default port 6806) containing ../ or ..%2F sequences in the URL path, particularly targeting /appearance/../../ patterns; unexpected outbound connections from the SiYuan host following such requests.
  • Logs: Web server or application access logs showing requests to /appearance/ with path traversal sequences (e.g., GET /appearance/../../data/conf.json); HTTP 200 responses to such requests indicating successful file reads.
  • File System: No direct file system artifacts from read-only exploitation, but review of recently accessed sensitive files (e.g., conf.json, API token files) may indicate unauthorized access.
  • Process: No unusual child processes expected from this read-only vulnerability, but monitor for subsequent suspicious activity following credential exposure (Security Advisory).

Mitigation and workarounds

Upgrade SiYuan to version 3.6.2 or later, which adds a util.IsSubPath(appearancePath, filePath) check to enforce directory confinement before serving files (Patch Commit). Until patching is complete, implement network-level access controls (firewall rules, VPN, or reverse proxy authentication) to restrict access to the SiYuan service port (default 6806) to trusted users only. Additionally, review and rotate any API tokens or secrets that may have been exposed, and audit access logs for signs of exploitation (Security Advisory).

Community reactions

The vulnerability was reported by security researcher mith36 and disclosed via GitHub's coordinated vulnerability disclosure process. Brief social media activity was observed on Mastodon and Bluesky shortly after publication, consistent with routine CVE announcement traffic. No major vendor statements or notable researcher commentary beyond the advisory itself have been identified.

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management