CVE-2026-87815 | siyuan-note SiYuan up to 3.8.1 /api/riff/removeRiffDeck deckID path traversal (EUVD-2026-74841)
A vulnerability classified as problematic has been found in siyuan-note SiYuan up to 3.8.1. This affects an unknown function of the file /api/riff/removeRiffDeck. Performing a manipulation of the argument deckID results in path traversal.
This vulnerability was named CVE-2026-87815. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More