0day Signal@0dayPublishingDisclosure
The post announces a directory traversal vulnerability in SiYuan’s `/api/file/readDir` endpoint, providing a link to a detailed report and outlining the technical issue, but it does not mention exploit code, active exploitation, or patch information.
PulsePatch.io@pulsepatchioDisclosure
A critical directory traversal flaw (CVE-2026-33670) in the SiYuan publishing service has been disclosed; administrators should keep an eye out for forthcoming official patches.
CVEFind.com@CveFindComPatch
SiYuan released version 3.6.2 to patch CVE‑2026‑33670, fixing a vulnerability in the /api/file/readDir endpoint, with no exploitation details disclosed.
The Hacker Wire@TheHackerWireDisclosure
CVE-2026-33670 is a critical directory traversal vulnerability in SiYuan’s /api/file/readDir endpoint, allowing enumeration of all document names prior to version 3.6.2.
CVE@CVEnewDisclosure
The CVE highlights a directory traversal flaw in SiYuan's /api/file/readDir endpoint prior to v3.6.2, allowing retrieval of file names, but no PoC, exploit, or patch information is provided.