THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-7hm9-v7vf-7g4w (high) — SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure

[GHSA] GHSA-7hm9-v7vf-7g4w (high) — SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure

medgithub_advisoriesPublished 2026-09-03

GHSA-7hm9-v7vf-7g4w Severity: high CVE: CVE-2026-69086

SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure

**CVE:** This vulnerability corresponds to CVE-2026-69086.

### Summary

Four attribute-view read endpoints build a filesystem path from a caller-cont

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-7hm9-v7vf-7g4w