BRIEFING NOTE: CVE-2026-40318 OVERVIEW SiYuan, an open-source personal knowledge management system, contains a critical path traversal vulnerability in versions 3.6.3 and earlier. The /api/av/removeUnusedAttributeView endpoint fails to properly validate the user-controlled id parameter, allowing attackers to inject path traversal sequences and escape the intended directory structure. SEVERITY This vulnerability carries a CVSS 3.1 score of 8.5 (HIGH) with a network-based attack vector requiring only low complexity and valid user credentials. The attack requires no user interaction and impacts system confidentiality through arbitrary file deletion, including critical configuration files and workspace metadata. The high availability impact reflects the potential for widespread system disruption through deletion of essential .json files. EXPLOITATION STATUS Current exploitation activity remains minimal, with an EPSS score of 0.00066 indicating lower prevalence relative to other known vulnerabilities. The CVE is not currently tracked on the Known Exploited Vulnerabilities (KEV) catalog and shows no active listing on security hotlists. However, the straightforward nature of the vulnerability and availability of details suggests exploitation could accelerate if not promptly patched. Organizations running affected versions should prioritize immediate upgrade to version 3.6.4 where the issue has been remediated.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.6.4CPE matchmatch criteria | cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.