Executive brief
SiYuan is a note-taking and knowledge-management application with a marketplace feature (Bazaar) for plugins, themes, widgets, and templates. Authenticated administrators can exploit a path-traversal vulnerability in the install and uninstall endpoints to write arbitrary files anywhere on the system or recursively delete directories, potentially compromising system integrity and availability.
Technical details
The vulnerability is a path-traversal (CWE-22) in the Bazaar marketplace endpoints across all ten install/uninstall operations (plugins, widgets, icons, templates, themes). The vulnerable function getPackageInstallPath() directly concatenates the user-supplied packageName parameter into a file path via filepath.Join() without any validation, allowing attackers to inject directory-traversal sequences like ../../../../. On install, crafted packageName values cause downloaded packages to be written to arbitrary filesystem locations; on uninstall, os.RemoveAll() is invoked on the traversed path, enabling recursive deletion of arbitrary directories. All affected endpoints require admin authentication (CheckAuth + CheckAdminRole), but threats include compromised admin sessions, malicious plugins with full Node.js access, and prompt-injected AI agents. The fix was released in version 3.7.4.
Affected products
- SiYuan SiYuan before 3.7.4
Timeline
- 2026-08-21: disclosed
- 2026: patched: patched version v3.7.4