CVE-2026-33669Disclosure(b3log / siyuan)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch b3log siyuan systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SiYuan is a personal knowledge management system. Prior to version 3.6.2, document IDs were retrieved via the /api/file/readDir interface, and then the /api/block/getChildBlocks interface was used to view the content of all documents. Version 3.6.2 patches the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • siyuan

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-26); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
siyuan

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-26: 3Mentions · 2026-03-27: 2PoC Mentioned / Linked · 2026-03-27: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-26: 3Technical Details · 2026-03-27: 103-2603-27
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-263
Disclosure2Patch1
2026-03-272
Disclosure1Patch1
Full discourse5 posts
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33669: SiYuan has Arbitrary Document Re... Publishing service exposes document enumeration via /api/file/readDir + content exfiltration through /api/block/getChil... https://zerodaysignal.com/vulnerability/CVE-2026-33669 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    SiYuan’s publishing service is vulnerable to CVE-2026-33669, allowing arbitrary document enumeration and content exfiltration through specific API endpoints, as detailed in the linked zero days report.

    0000061
    194 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    An arbitrary document reading vulnerability (CVE-2026-33669) affects the `SiYuan` publishing service. Review configurations to restrict access. #SiYuan #InfoSec #Vulnerability https://www.pulsepatch.io/posts/cve-2026-33669-siyuan-arbitrary-document-reading

    Post summary

    The text announces CVE‑2026‑33669 as an arbitrary document reading flaw in SiYuan and recommends restricting access configurations as a mitigation.

    0000028
    6 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33669 - Critical SiYuan is a personal knowledge management system. Prior to version 3.6.2, document IDs were retrieved via the /api/file/readDir interface, and then the /api/block/getChildBlocks interface... https://www.thehackerwire.com/vulnerability/CVE-2026-33669/ https://t.co/Z6zCortdPs

    Post summary

    A critical CVE-2026-33669 was disclosed for SiYuan, highlighting that document IDs were exposed via the /api/file/readDir and /api/block/getChildBlocks interfaces prior to the 3.6.2 update.

    0000043
    163 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33669: CRITICAL] Update to SiYuan version 3.6.2 for improved cyber security! Prior versions had a vulnerability allowing access to document IDs and content. Patched in the latest release.#cve,CVE-2026-33669,#cybersecurity https://cvefind.com/CVE-2026-33669

    Post summary

    The CVE-2026-33669 vulnerability exposed document IDs and content in earlier SiYuan versions, but the issue has been patched in release 3.6.2, with no evidence of active exploitation or PoC.

    0000037
    617 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33669 SiYuan is a personal knowledge management system. Prior to version 3.6.2, document IDs were retrieved via the /api/file/readDir interface, and then the /api/block/get… https://www.cve.org/CVERecord?id=CVE-2026-33669

    Post summary

    The text merely discloses that SiYuan versions prior to 3.6.2 allow document IDs to be retrieved through specific API endpoints, with no evidence of a Proof of Concept, exploit code, or active exploitation.

    0000048
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appb3logsiyuan---

Explore more