CVE-2026-33669: b3log Siyuan

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

SiYuan is a personal knowledge management system. Prior to version 3.6.2, document IDs were retrieved via the /api/file/readDir interface, and then the /api/block/getChildBlocks interface was used to view the content of all documents. Version 3.6.2 patches the issue.

Affected products

  • b3log Siyuan: before 3.6.2 (fixed in 3.6.2)

Published 2026-03-26. Last modified 2026-06-17.