CVE-2026-32749: SiYuan importSY/importZipMd: path traversal via multipart filename enables arbitrary file write
POST /api/import/importSY and POST /api/import/importZipMd write uploaded archives to a path derived from the multipart filename field without sanitization, allowing an admin to write files to arbitrary locations outside the temp directory — including system paths that enable RCE.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-32749 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →