{"id":"GHSA-xxm9-w59q-m66x","title":"Duplicate Advisory: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem","summary":"Duplicate Advisory: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem","severity":"medium","cvss":5.8,"cwe":["CWE-862"],"vendor":"siyuan-note","product":"github.com/siyuan-note/siyuan/kernel","ecosystem":"go","affected":["github.com/siyuan-note/siyuan/kernel < 3.7.4"],"published":"2026-08-13","updated":"2026-10-01","sourceUpdated":"2026-10-01T15:45:49Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-xxm9-w59q-m66x","references":[{"url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-hf8h-97gm-4x2p"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73605"},{"url":"https://www.vulncheck.com/advisories/siyuan-before-path-traversal-via-getuniquefilename"},{"url":"https://github.com/advisories/GHSA-xxm9-w59q-m66x"}],"tags":["ghsa","go"],"ingestedAt":"2026-10-01T15:48:17.818Z","slug":"GHSA-xxm9-w59q-m66x","body":"## Overview\n\n## Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of GHSA-hf8h-97gm-4x2p. This link is maintained to preserve external references.\n\n## Original Description\nSiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that allows anonymous readers to probe filesystem existence without validation or confinement. Attackers can supply arbitrary absolute paths to determine whether files and directories exist on the host, enabling reconnaissance of the filesystem layout and installed software.\n\n## Affected packages\n\n- `github.com/siyuan-note/siyuan/kernel < 3.7.4`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":31.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}