CVE-2026-32938Disclosure(b3log / siyuan)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch b3log siyuan systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the /api/lute/html2BlockDOM on the desktop copies local files pointed to by file:// links in pasted HTML into the workspace assets directory without validating paths against a sensitive-path list. Together with GET /assets/*path, which only requires authentication, a publish-service visitor can cause the desktop kernel to copy any readable sensitive file and then read it via GET, leading to exfiltration of sensitive files. This issue has been fixed in version 3.6.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-200CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • siyuan

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 4 mentions (2026-03-20); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
siyuan

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-03-19: 1Mentions · 2026-03-20: 4Mentions · 2026-03-22: 1Mentions · 2026-03-23: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-20: 4Technical Details · 2026-03-22: 1Technical Details · 2026-03-23: 103-1903-2003-2203-23
Signal classification2 categories
Disclosure
685.7%
Patch
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-191
Disclosure1
2026-03-204
Disclosure3Patch1
2026-03-221
Disclosure1
2026-03-231
Disclosure1
Full discourse7 posts
  • maruomosquit@maru1151157
    Disclosure

    🚨 CVE-2026-32938 (CVSS: 9.9) SiYuan 3.6.0以下では、file://リンクのローカルファイルをワークスペースにコピーし、認証不要でアセット取得可能。敏感データ漏洩のリスクあり。3.6.1で修正。 https://maruomosquit.com/vulnerability/CVE-2026-32938/ #脆弱性 #セキュリティ

    Post summary

    CVE-2026-32938 enables unauthenticated local file access via file:// links in SiYuan <=3.6.0, potentially leaking sensitive data; patch available in 3.6.1.

    0003081
    1.7K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-32938 - Critical SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the /api/lute/html2BlockDOM on the desktop copies local files pointed to by file:// links in pasted HTML int... https://www.thehackerwire.com/vulnerability/CVE-2026-32938/ https://t.co/utpOv7OLLL

    Post summary

    The text announces the discovery of CVE‑2026‑32938, providing technical details about the vulnerability but no evidence of exploitation, patches, or PoC.

    0000025
    142 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32938: SiYuan has an Arbitrary File Rea... SiYuan's HTML paste feature weaponizes file:// links to copy arbitrary files into /assets/, turning knowledge managemen... https://zerodaysignal.com/vulnerability/CVE-2026-32938 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces the discovery of a new vulnerability (CVE‑2026‑32938) in SiYuan’s HTML paste feature that allows arbitrary file reads via file:// links, but offers no PoC, exploit code, or claim of active exploitation.

    0000052
    155 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32938 Local File Exfiltration in SiYuan Knowledge Management System Before 3.6.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32938

    Post summary

    The content identifies CVE‑2026‑32938 as a local file exfiltration flaw in SiYuan Knowledge Management System (pre‑3.6.1) with minimal technical detail, serving primarily as a disclosure.

    0000033
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-32938: CRITICAL] Vulnerability in SiYuan versions 3.6.0 &amp; below allowed unauthorized access to sensitive files on desktops. Update to version 3.6.1 to resolve this security flaw.#cve,CVE-2026-32938,#cybersecurity https://cvefind.com/CVE-2026-32938

    Post summary

    The post reports a critical file‑access vulnerability in SiYuan versions 3.6.0 and below and urges users to upgrade to 3.6.1 to mitigate the issue.

    0000040
    604 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32938 SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the /api/lute/html2BlockDOM on the desktop copies local files pointed to by file:// lin… https://www.cve.org/CVERecord?id=CVE-2026-32938

    Post summary

    CVE‑2026‑32938 affects SiYuan 3.6.0 and earlier through the /api/lute/html2BlockDOM endpoint, allowing the application to copy local files referenced via file:// URLs; no proof of concept, exploit, patch, or active exploitation is reported yet.

    0000036
    56.8K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical arbitrary file read vulnerability (CVE-2026-32938) affects `SiYuan`'s Desktop Publish Service, leading to potential information disclosure. Assess exposure and monitor for updates. #infosec #vulnerability #desktopsecurity https://www.pulsepatch.io/posts/cve-2026-32938-siyuan-arbitrary-file-read

    Post summary

    The post announces a critical arbitrary file read vulnerability (CVE‑2026‑32938) in SiYuan’s Desktop Publish Service that could expose sensitive data, urging users to evaluate exposure and watch for vendor updates.

    0000034
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appb3logsiyuan---

Explore more