
CVE-2026-40259 SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, the /api/av/removeUnusedAttributeView endpoint is protected only by generi… https://www.cve.org/CVERecord?id=CVE-2026-40259
Post summary
The CVE describes an insufficiently protected API endpoint in SiYuan, with no available PoC, exploit details, or mitigation information provided.
