THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-275h-v5h9-vr82 (high) — Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db

[GHSA] GHSA-275h-v5h9-vr82 (high) — Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db

medgithub_advisoriesPublished 2026-09-02

GHSA-275h-v5h9-vr82 Severity: high CVE: CVE-2026-59832

Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db

Reporter: Cavan Loughran, Celvex Group Inc.

Summary ------- The /snippets/*filepath route handler serveSnippets in kernel/server/serve.go performs a bare filepath.Join(util.SnippetsPath, filePath) on the single-decode

Indicators of compromise

Original source: https://github.com/advisories/GHSA-275h-v5h9-vr82