Skip to content

SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894

High severity GitHub Reviewed Published Jun 3, 2026 in siyuan-note/siyuan

No open alerts for this advisory

Give feedback on Dependabot alerts