maruomosquit[verified]@maru1151157Disclosure
CVE-2026-32938 enables unauthenticated local file access via file:// links in SiYuan <=3.6.0, potentially leaking sensitive data; patch available in 3.6.1.
The Hacker Wire@TheHackerWireDisclosure
The text announces the discovery of CVE‑2026‑32938, providing technical details about the vulnerability but no evidence of exploitation, patches, or PoC.
0day Signal@0dayPublishingDisclosure
The post announces the discovery of a new vulnerability (CVE‑2026‑32938) in SiYuan’s HTML paste feature that allows arbitrary file reads via file:// links, but offers no PoC, exploit code, or claim of active exploitation.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The content identifies CVE‑2026‑32938 as a local file exfiltration flaw in SiYuan Knowledge Management System (pre‑3.6.1) with minimal technical detail, serving primarily as a disclosure.
CVEFind.com@CveFindComPatch
The post reports a critical file‑access vulnerability in SiYuan versions 3.6.0 and below and urges users to upgrade to 3.6.1 to mitigate the issue.
CVE@CVEnewDisclosure
CVE‑2026‑32938 affects SiYuan 3.6.0 and earlier through the /api/lute/html2BlockDOM endpoint, allowing the application to copy local files referenced via file:// URLs; no proof of concept, exploit, patch, or active exploitation is reported yet.
PulsePatch.io@pulsepatchioDisclosure
The post announces a critical arbitrary file read vulnerability (CVE‑2026‑32938) in SiYuan’s Desktop Publish Service that could expose sensitive data, urging users to evaluate exposure and watch for vendor updates.