Retour à la veille

CVE-2026-87815

Publié : 9 septembre 2026
Modifié : 9 septembre 2026
Lien officiel NVD
Score CVSS
8.7
HIGH

Description détaillée

SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck endpoint that fails to validate the deckID parameter. An authenticated administrator can supply path traversal sequences to delete arbitrary .deck and .cards files outside the workspace directory.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H

Références et Patchs