CVE-2026-32750General(b3log / siyuan)

LOWCVSS 6.8 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importStdMd passes the localPath parameter directly to model.ImportFromLocalPath with zero path validation. The function recursively reads every file under the given path and permanently stores their content as SiYuan note documents in the workspace database, making them searchable and accessible to all workspace users. Data persists in the workspace database across restarts and is accessible to Publish Service Reader accounts. Combined with the renderSprig SQL injection ( separate advisory ), a non-admin user can then read all imported secrets without any additional privileges. This issue has been fixed in version 3.6.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-552

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • siyuan

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
siyuan

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-20: 2Technical Details · 2026-03-20: 203-20
Signal classification1 categories
General
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-32750 SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importStdMd passes the localPath parameter directly to model.ImportFro… https://www.cve.org/CVERecord?id=CVE-2026-32750

    Post summary

    The text briefly details CVE‑2026‑32750, noting that a localPath parameter is forwarded to an import function in SiYuan versions 3.6.0 and below, but it provides no PoC, exploit, patch, or evidence of real‑world attacks.

    00010313
    56.8K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-32750 SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importStdMd passes the localPath parameter directly to model.ImportFro… https://www.cve.org/CVERecord?id=CVE-2026-32750 ----- Traducción: CVE-2026-32750 SiY… http://infoflow.cloud`

    Post summary

    The post briefly identifies CVE‑2026‑32750 in SiYuan, noting a localPath parameter flaw but provides no PoC, exploit, patch, or evidence of active use.

    0000041
    61 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appb3logsiyuan---

Explore more