
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33476 is an unauthenticated arbitrary file read vulnerability in SiYuan, a self-hosted personal knowledge management application, caused by improper path sanitization (path traversal). It affects all versions up to and including v3.6.1, and was patched in v3.6.2. The vulnerability was published on March 20, 2026, with a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Security Advisory).
The root cause is a combination of CWE-22 (Path Traversal) and CWE-73 (External Control of File Name or Path) in kernel/server/serve.go. The /appearance/*filepath endpoint constructs a filesystem path using filepath.Join(appearancePath, strings.TrimPrefix(c.Request.URL.Path, "/appearance/")) without sanitizing or normalizing the user-supplied path component, allowing ../ sequences to escape the intended appearancePath directory. Critically, the authentication middleware in session.go explicitly skips authentication for any request prefixed with /appearance/, meaning no credentials are required to exploit this endpoint. The resolved path is then served directly via c.File(filePath) without any boundary verification (Security Advisory, Patch Commit).
Successful exploitation allows an unauthenticated remote attacker to read any file accessible to the SiYuan server process, including workspace configuration files, user notes and stored data, API tokens and secrets, and local system files depending on OS-level permissions. This can lead to sensitive information disclosure, credential leakage, and further system compromise through exposed secrets. There is no integrity or availability impact, but the confidentiality impact is rated High (Security Advisory).
A public proof-of-concept (PoC) exploit is available in the GitHub security advisory, consisting of a simple curl command requiring no authentication or special tooling. No credentials or prior access are required, and attack complexity is low. The EPSS score is approximately 0.352% (58th percentile), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing. A Nuclei template for automated detection was also added to the ProjectDiscovery nuclei-templates repository (GitHub Advisory, Security Advisory).
http://<target>:6806./appearance/ endpoint, e.g., http://<target>:6806/appearance/../../data/conf.json to read the workspace configuration file.curl with the --path-as-is flag to prevent the HTTP client from normalizing the ../ sequences before sending:curl -v --path-as-is "http://<target>:6806/appearance/../../data/conf.json"/etc/passwd on Linux) based on the server process permissions.../ or ..%2F sequences in the URL path, particularly targeting /appearance/../../ patterns; unexpected outbound connections from the SiYuan host following such requests./appearance/ with path traversal sequences (e.g., GET /appearance/../../data/conf.json); HTTP 200 responses to such requests indicating successful file reads.conf.json, API token files) may indicate unauthorized access.Upgrade SiYuan to version 3.6.2 or later, which adds a util.IsSubPath(appearancePath, filePath) check to enforce directory confinement before serving files (Patch Commit). Until patching is complete, implement network-level access controls (firewall rules, VPN, or reverse proxy authentication) to restrict access to the SiYuan service port (default 6806) to trusted users only. Additionally, review and rotate any API tokens or secrets that may have been exposed, and audit access logs for signs of exploitation (Security Advisory).
The vulnerability was reported by security researcher mith36 and disclosed via GitHub's coordinated vulnerability disclosure process. Brief social media activity was observed on Mastodon and Bluesky shortly after publication, consistent with routine CVE announcement traffic. No major vendor statements or notable researcher commentary beyond the advisory itself have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."