THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-82650 (MEDIUM 4.4) — SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the RenderTemplate function (kernel/model/template.go), reachable via the POST /api/template/render endpoint (kernel/api/template.go). The endpoint restricts the supplied path only to the workspace

[NVD] CVE-2026-82650 (MEDIUM 4.4) — SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the RenderTemplate function (kernel/model/template.go), reachable via the POST /api/template/render endpoint (kernel/api/template.go). The endpoint restricts the supplied path only to the workspace

mednvdPublished 2026-08-30

CVE-2026-82650 CVSS: 4.4 MEDIUM Published: 2026-08-30T15:16:45.610

SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the RenderTemplate function (kernel/model/template.go), reachable via the POST /api/template/render endpoint (kernel/api/template.go). The endpoint restricts the supplied path only to the workspace directory (util.IsAbsPathInWorkspace) but, unlike th

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82650