THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-82651 (MEDIUM 4.9) — SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*path and /repo/diff/*path endpoints in kernel/server/serve.go. These routes require admin authentication but construct file paths independently, so an authenticat

[NVD] CVE-2026-82651 (MEDIUM 4.9) — SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*path and /repo/diff/*path endpoints in kernel/server/serve.go. These routes require admin authentication but construct file paths independently, so an authenticat

mednvdPublished 2026-08-30

CVE-2026-82651 CVSS: 4.9 MEDIUM Published: 2026-08-30T15:16:45.753

SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*path and /repo/diff/*path endpoints in kernel/server/serve.go. These routes require admin authentication but construct file paths independently, so an authenticated administrator can retrieve historical snapshots o

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82651