CVE-2026-74798 | siyuan-note SiYuan up to 3.7.3 database_clean MCP tool attribute_view.go RemoveUnusedAttributeView ID path traversal
A vulnerability was found in siyuan-note SiYuan up to 3.7.3. It has been classified as critical. This impacts the function RemoveUnusedAttributeView of the file kernel/model/attribute_view.go of the component database_clean MCP tool. The manipulation of the argument ID leads to path traversal.
This vulnerability is referenced as CVE-2026-74798. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More