CVE-2026-25992 | SiYuan up to 3.5.4 Endpoint /api/file/getFile path traversal (GHSA-f72r-2h5j-7639)
A vulnerability was found in SiYuan up to 3.5.4. It has been rated as critical. This vulnerability affects unknown code of the file /api/file/getFile of the component Endpoint. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2026-25992. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.