HIGHVulnerability

CVE-2026-87815

SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck endpoint that fails to validate the deckID parameter. An authenticated administrator can supply path traversal sequences to delete arbitrary .deck and .cards files outside the workspace directory.

Properties

severity
HIGH
score
8.7
cve_id
CVE-2026-87815
signal_observed_at
2026-09-17T21:32:24+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
published_at
2026-09-09T12:17:16.537
last_modified
2026-09-14T14:17:17.650

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]External Control of File Name or Path

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-87815 — Ninja Signal Threat Intelligence | Ninja Signal