CVE-2026-30869Disclosure(b3log / siyuan)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch b3log siyuan systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in the /export endpoint allows an attacker to read arbitrary files from the server filesystem. By exploiting double‑encoded traversal sequences, an attacker can access sensitive files such as conf/conf.json, which contains secrets including the API token, cookie signing key, and workspace access authentication code. Leaking these secrets may enable administrative access to the SiYuan kernel API, and in certain deployment scenarios could potentially be chained into remote code execution (RCE). This vulnerability is fixed in 3.5.10.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • siyuan

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-03-10); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Vendors
Products
siyuan

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-03-09: 1Mentions · 2026-03-10: 2Mentions · 2026-03-23: 1Mentions · 2026-04-23: 1Mentions · 2026-04-24: 1Mentions · 2026-09-02: 1PoC Mentioned / Linked · 2026-03-09: 1Patch / Workaround · 2026-03-10: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 2Technical Details · 2026-03-23: 1Technical Details · 2026-04-23: 1Technical Details · 2026-09-02: 103-0903-1003-2304-2304-2409-02
Signal classification3 categories
Disclosure
571.4%
Patch
114.3%
General
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-091
Disclosure1
2026-03-102
Disclosure1Patch1
2026-03-231
Disclosure1
2026-04-231
General1
2026-04-241
Disclosure1
2026-09-021
Disclosure1
Full discourse7 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30869 Path Traversal in SiYuan Knowledge Management System Exposes Sensitive Secrets https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30869

    Post summary

    The text announces a Path Traversal vulnerability (CVE-2026-30869) in SiYuan Knowledge Management System that could expose sensitive secrets, without providing PoC, exploit code, or patch information.

    0001039
    4.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 SiYuan Note, Path Traversal (serveSnippets), #CVE-2026-30869 (High) -DC-Sep2026-2085 https://dailycve.com/siyuan-note-path-traversal-servesnippets-cve-2026-30869-high-dc-sep2026-2085/

    Post summary

    The post announces a high‑severity path traversal flaw in SiYuan Note (CVE‑2026‑30869) and directs readers to a detailed article on dailycve.com. It provides basic technical details but no PoC, exploit code, mitigation, or evidence of active exploitation.

    0000036
    233 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41894 SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, the fix for CVE-2026-30869 only added a denylist check (IsSensitivePath) but did not ad… https://www.cve.org/CVERecord?id=CVE-2026-41894

    Post summary

    The text refers to CVE-2026-41894 in the context of a prior release fix and links to the CVE record, but offers no PoC, exploit, or patch details.

    0000075
    57.2K followersView on X
  • DailyCVE@dailycve
    General

    🔴 SiYuan, Path Traversal, #CVE-2026-30869 (High) https://dailycve.com/siyuan-path-traversal-cve-2026-30869-high/

    Post summary

    The snippet only notes a high‑severity path traversal flaw (CVE‑2026‑30869) in SiYuan, without mentioning any PoC, exploit code, active attacks, or patch information.

    0000038
    183 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `SiYuan` is vulnerable to a path traversal flaw (CVE-2026-30869) in its /export endpoint, allowing arbitrary file read and secret leakage. #SiYuan #PathTraversal #CyberSecurity https://www.pulsepatch.io/posts/cve-2026-30869-siyuan-path-traversal

    Post summary

    The post announces a path traversal vulnerability (CVE‑2026‑30869) in SiYuan’s /export endpoint that can lead to arbitrary file reads, without mention of exploits, patches, or active exploitation.

    0000022
    2 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-30869: CRITICAL] Critical vulnerability in SiYuan's /export endpoint (pre-3.5.10) allowed file system access. Patched in 3.5.10. Update immediately to mitigate risk of remote code execution.#cve,CVE-2026-30869,#cybersecurity https://cvefind.com/CVE-2026-30869

    Post summary

    CVE-2026-30869 is a critical issue in SiYuan's /export endpoint that enabled file‑system access and potential remote code execution; the flaw was fixed in version 3.5.10, so updating is essential.

    0000034
    601 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-30869: SiYuan has a Path Traversal in /... Double-encoded path traversal in SiYuan's /export endpoint leaks API tokens and workspace secrets - classic bypass that... https://zerodaysignal.com/vulnerability/CVE-2026-30869 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    SiYuan suffers a double‑encoded path traversal in its /export endpoint that can expose API tokens and workspace secrets, with a vulnerability page linked for more details.

    0000072
    140 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appb3logsiyuan---

Explore more