
CVE-2026-40318 SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem pat… https://www.cve.org/CVERecord?id=CVE-2026-40318
Post summary
The CVE-2026-40318 record reveals a vulnerable endpoint in SiYuan versions 3.6.3 and earlier that constructs a filesystem path. No exploit, patch, or active exploitation information is provided in this snippet.
