CVE-2026-23851 | SiYuan up to 3.5.3 globalCopyFiles path traversal (ID 16860 / EUVD-2026-3291)
A vulnerability described as critical has been identified in SiYuan up to 3.5.3. The affected element is an unknown function of the file /api/file/globalCopyFiles. Such manipulation leads to path traversal.
This vulnerability is traded as CVE-2026-23851. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.