CVE-2026-33670: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-33670 is a directory traversal vulnerability in SiYuan, an open-source personal knowledge management and note-taking application developed by b3log. The vulnerability exists in the /api/file/readDir interface of SiYuan's publishing service, allowing unauthenticated remote attackers to enumerate the entire directory structure of a notebook and, when chained with a file reading vulnerability, achieve arbitrary document reading. It affects SiYuan versions up to and including 3.6.1, with version 3.6.2 containing the fix. The vulnerability was published on March 23, 2026, and carries a CVSS v3.1 base score of 7.5 (High) per Feedly/NVD, though the GitHub Advisory rates it 9.8 (Critical) (GitHub Advisory, SiYuan Advisory).

Technical details

The root cause is improper limitation of a pathname to a restricted directory (CWE-22 / Path Traversal). The /api/file/readDir API endpoint accepts a path parameter via HTTP POST without proper authentication checks or path sanitization, allowing any network-accessible client to supply arbitrary directory paths such as data or conf and receive a full listing of files and subdirectories in response. By recursively calling this endpoint, an attacker can map the complete notebook directory structure, including resource folders, plugin folders, and configuration directories. A public proof-of-concept Python script is available that automates this traversal by iterating through directories up to a configurable depth (GitHub Advisory, SiYuan Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to enumerate the complete directory and file structure of a SiYuan notebook, exposing the names and organization of all documents, resources, plugins, and configuration files. When chained with a separate file reading vulnerability, this can escalate to arbitrary document reading, potentially exposing sensitive personal notes, credentials stored in configuration files, and plugin data. The primary impact is a high confidentiality loss, with no direct integrity or availability impact from the traversal itself (GitHub Advisory, SiYuan Advisory).

Exploitability

A functional proof-of-concept Python exploit is publicly available in the GitHub Security Advisory, demonstrating unauthenticated directory traversal against a live SiYuan instance via the /api/file/readDir endpoint (SiYuan Advisory). No authentication or special privileges are required, and exploitation requires only network access to the SiYuan instance. There is no confirmed evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.063% (low probability of exploitation in the next 30 days), and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or locally accessible SiYuan instances running version 3.6.1 or earlier. SiYuan typically listens on port 6806 by default.
  2. Confirm vulnerability: Send an unauthenticated HTTP POST request to /api/file/readDir with the JSON body {"path": "data"} and verify the response returns a directory listing with "code": 0.
  3. Enumerate directory structure: Use the public PoC script or manually iterate through directories by supplying paths such as data, conf, data/<notebook-id>, etc., recursively traversing subdirectories to map the full notebook structure.
  4. Identify sensitive targets: From the directory listing, identify documents, configuration files (conf/ folder), plugin directories, and resource folders of interest.
  5. Chain with file read vulnerability: Leverage a companion file reading vulnerability (referenced in the advisory) to read the contents of specific files identified during traversal, achieving arbitrary document disclosure (SiYuan Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Repeated unauthenticated HTTP POST requests to /api/file/readDir from external or unexpected IP addresses; high volume of requests to this endpoint in a short time window suggesting automated traversal.
  • Logs: SiYuan access logs showing POST requests to /api/file/readDir with varying path values (e.g., data, conf, data/<id>) from a single source IP; requests without valid authentication tokens.
  • File System: Presence of a readdir.json file in attacker-controlled locations (created by the PoC script to save enumeration results); no direct file system artifacts on the server from traversal alone.
  • Process: Unusual outbound connections from the SiYuan process if chained with further exploitation steps (SiYuan Advisory).

Mitigation and workarounds

Users should upgrade SiYuan to version 3.6.2 or later, which contains the patch for this vulnerability (SiYuan Advisory). As an interim workaround, restrict network access to the SiYuan instance using firewall rules or by binding the service to localhost only, preventing unauthenticated external access to the API. Additionally, review access logs for signs of unauthorized directory enumeration attempts against the /api/file/readDir endpoint.

Community reactions

The vulnerability was reported by security researcher CongSec and disclosed via the GitHub Security Advisory program on March 23, 2026 (SiYuan Advisory). Coverage appeared on The Hacker Wire and was noted on Mastodon and Bluesky shortly after disclosure. The vulnerability was also covered alongside a related SiYuan information disclosure CVE (CVE-2026-33669) and a stored XSS vulnerability (CVE-2026-34448), suggesting a broader security review of the SiYuan application around this period.

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management