CVE-2026-54066 | SiYuan up to 3.6.x Publish Mode conf/conf.json path traversal (GHSA-p4m3-mgmm-c664)

SecurityVulns

A vulnerability identified as critical has been detected in SiYuan up to 3.6.x. This impacts an unknown function of the file conf/conf.json of the component Publish Mode. The manipulation leads to path traversal.

This vulnerability is listed as CVE-2026-54066. The attack may be initiated remotely. There is no available exploit.

You should upgrade the affected component.VulDB Recent EntriesRead More