CrowdSecLive Exploit Tracker
Limited ExploitationCVE-2026-54066Public Exploit

SiYuan - Path Traversal (CVE-2026-54066)

PublishedJun 19, 2026
First SeenJun 25, 2026
Last Seen
Reported
CVSS7.5
web_application

Description

SiYuan (versions <= 3.6.5) is affected by an unauthenticated path traversal vulnerability in its /assets/ file-serving route. The endpoint fails to properly sanitize double URL-encoded traversal sequences (e.g. %252e%252e/), allowing an unauthenticated attacker to escape the assets directory and read arbitrary files accessible to the server process. Instances running in publish mode (default port 6808) are particularly exposed, where retrieving conf/conf.json leaks sensitive data such as API tokens and authentication hashes.

psychologyCrowdSec Analysis

CVE-2026-54066 is a newly identified vulnerability, but specific details regarding its nature, affected components, and potential impact have not yet been disclosed. As information becomes available, organizations should monitor official advisories to assess risk and determine appropriate mitigation steps.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

According to CrowdSec data, while opportunistic exploitation dominates, a portion of threat actors trying to exploit CVE-2026-54066 apply basic targeting methods such as port or service detection. This indicates emerging patterns of selective targeting. Data from the CrowdSec community also indicates a gradual decrease in attacks targeting CVE-2026-54066. While still present in the wild, exploitation levels have dropped noticeably week-over-week. This may signal that the vulnerability is becoming less relevant or that defenses are improving fast enough for attackers to lose interest.

Attackers exploit double URL-encoded path traversal sequences such as /assets/%252e%252e/%252e%252e/ to access sensitive files like conf/conf.json on SiYuan servers running in publish mode (port 6808).

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2026-06-19
Rule Released2026-06-24
CrowdSec First Seen2026-06-25

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.