Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40318

27
FAUCET Score

BRIEFING NOTE: CVE-2026-40318 OVERVIEW SiYuan, an open-source personal knowledge management system, contains a critical path traversal vulnerability in versions 3.6.3 and earlier. The /api/av/removeUnusedAttributeView endpoint fails to properly validate the user-controlled id parameter, allowing attackers to inject path traversal sequences and escape the intended directory structure. SEVERITY This vulnerability carries a CVSS 3.1 score of 8.5 (HIGH) with a network-based attack vector requiring only low complexity and valid user credentials. The attack requires no user interaction and impacts system confidentiality through arbitrary file deletion, including critical configuration files and workspace metadata. The high availability impact reflects the potential for widespread system disruption through deletion of essential .json files. EXPLOITATION STATUS Current exploitation activity remains minimal, with an EPSS score of 0.00066 indicating lower prevalence relative to other known vulnerabilities. The CVE is not currently tracked on the Known Exploited Vulnerabilities (KEV) catalog and shows no active listing on security hotlists. However, the straightforward nature of the vulnerability and availability of details suggests exploitation could accelerate if not promptly patched. Organizations running affected versions should prioritize immediate upgrade to version 3.6.4 where the issue has been remediated.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.6.4CPE matchmatch criteria
cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.5HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
HIGH
Exploitability Score
3.1
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.29%
Probability of exploitation in next 30 days
EPSS Percentile
21.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0029 is in the 8th percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: github.com/siyuan-note/siyuan/kernelFixed in: 3.6.40.0.0-20260407035653-2f416e5253f1

Vendor Advisories (1)

goGHSA-vw86-c94w-v3x4high

SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`

Apr 10, 2026

References

github.com / siyuan-note/siyuan/releases/tag/v3.6.4
Release Notes
github.com / siyuan-note/siyuan/security/advisories/GHSA-vw86-c94w-v3x4
Third Party Advisory