
CVE-2026-59854 SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, POST /api/file/globalCopyFiles accepts attacker-supplied absolute source paths and reli… https://www.cve.org/CVERecord?id=CVE-2026-59854
Post summary
The text discloses that SiYuan versions before 3.7.1 have a path‑traversal flaw in the globalCopyFiles API where attacker‑supplied absolute paths can be used, but it provides no PoC, exploit code, patch, or evidence of active exploitation.
