THREAT OPS › Threat News › [NVD] CVE-2026-82651 (MEDIUM 4.9) — SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*path and /repo/diff/*path endpoints in kernel/server/serve.go. These routes require admin authentication but construct file paths independently, so an authenticat
[NVD] CVE-2026-82651 (MEDIUM 4.9) — SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*path and /repo/diff/*path endpoints in kernel/server/serve.go. These routes require admin authentication but construct file paths independently, so an authenticat
CVE-2026-82651 CVSS: 4.9 MEDIUM Published: 2026-08-30T15:16:45.753
SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*path and /repo/diff/*path endpoints in kernel/server/serve.go. These routes require admin authentication but construct file paths independently, so an authenticated administrator can retrieve historical snapshots o
Indicators of compromise
- CVE-2026-82651cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82651