---
id: GHSA-xxm9-w59q-m66x
title: >-
  Duplicate Advisory: getUniqueFilename passes an unvalidated client-supplied
  path to the filesystem, giving anonymous readers an existence oracle over the
  entire host filesystem
summary: >-
  Duplicate Advisory: getUniqueFilename passes an unvalidated client-supplied
  path to the filesystem, giving anonymous readers an existence oracle over the
  entire host filesystem
severity: medium
cvss: 5.8
cwe:
  - CWE-862
vendor: siyuan-note
product: github.com/siyuan-note/siyuan/kernel
ecosystem: go
affected:
  - github.com/siyuan-note/siyuan/kernel < 3.7.4
published: '2026-08-13'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:45:49Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-xxm9-w59q-m66x'
references:
  - url: >-
      https://github.com/siyuan-note/siyuan/security/advisories/GHSA-hf8h-97gm-4x2p
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73605'
  - url: >-
      https://www.vulncheck.com/advisories/siyuan-before-path-traversal-via-getuniquefilename
  - url: 'https://github.com/advisories/GHSA-xxm9-w59q-m66x'
tags:
  - ghsa
  - go
ingestedAt: '2026-10-01T15:48:17.818Z'
---

## Overview

## Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-hf8h-97gm-4x2p. This link is maintained to preserve external references.

## Original Description
SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that allows anonymous readers to probe filesystem existence without validation or confinement. Attackers can supply arbitrary absolute paths to determine whether files and directories exist on the host, enabling reconnaissance of the filesystem layout and installed software.

## Affected packages

- `github.com/siyuan-note/siyuan/kernel < 3.7.4`

## Remediation

Refer to the advisory for the patched release.
