CVE-2026-33670: b3log Siyuan

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to traverse and retrieve the file names of all documents under a notebook. Version 3.6.2 patches the issue.

Affected products

  • b3log Siyuan: before 3.6.2 (fixed in 3.6.2)

Published 2026-03-26. Last modified 2026-06-17.