CVE-2026-87815EPSS p39.2%

CVE-2026-87815CVE-2026-87815

Description

SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck endpoint that fails to validate the deckID parameter. An authenticated administrator can supply path traversal sequences to delete arbitrary .deck and .cards files outside the workspace directory.

Scoring

CVSS 8.7 ()
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
EPSS0.48% probability of exploitation · percentile 39.2% · 2026-10-05T12:00:23Z
Last modified2026-09-14
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.