Junglewise Threat Intelligence

CVE-2026-60084: SiYuan arbitrary file deletion in removeTemplate endpoint

CVE-2026-60084 · Severity: high · CVSS 8.7 · Published 2026-08-22

Technologies: SiYuan. Vendors: SiYuan.

Executive brief

SiYuan is a note-taking and knowledge management application. An authenticated admin user can delete arbitrary files and directories on the host system through an unvalidated API endpoint, potentially destroying critical application data, user files, or system configurations that the application process has permission to access.

Technical details

The /api/search/removeTemplate endpoint in SiYuan accepts a client-supplied "path" parameter that is passed directly to os.RemoveAll() without validation or base-directory restrictions. An authenticated administrator can supply absolute filesystem paths to recursively delete any file or directory the kernel process has permission to remove anywhere on the host. The vulnerability stems from the absence of path normalization, allowlist checks, or confinement to a templates directory. This CWE-22 path traversal variant requires admin authentication but can be exploited via CSRF, malicious plugins with Node.js access, or AI agents with tool-calling capabilities. The vulnerability was patched in v3.7.4.

Affected products

  • SiYuan SiYuan before 3.7.4

Timeline

  • 2026-08-22: disclosed
  • 2026-08-08: patched: v3.7.4 released

References

Related threats