SiYuan versions before v3.8.4 contain a path traversal vulnerability in the setNotebookIcon endpoint that allows authenticated administrators to create arbitrary directory trees and write files outside the workspace boundary. Attackers can supply directory traversal sequences in the notebook parameter to escape the workspace data directory and write conf.json files to arbitrary locations accessible by the kernel process.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-100638 is a path traversal vulnerability affecting SiYuan versions before v3.8.4 that allows authenticated administrators to escape the workspace boundary and write arbitrary files to the system. The vulnerability exists in the setNotebookIcon endpoint, where insufficient input validation on the notebook parameter permits directory traversal sequences (such as ../ patterns) to be exploited. This is particularly dangerous because it enables attackers with admin credentials to write configuration files like conf.json to locations accessible by the kernel process, potentially leading to arbitrary code execution or system compromise. Organizations running vulnerable SiYuan instances with administrative access controls are at risk, especially in environments where admin accounts may be compromised or insider threats are a concern.
While CVE-2026-100638 does not map directly to current MITRE ATT&CK techniques, Casky's security skills powered by Claude AI with extended reasoning would detect the attack patterns associated with this vulnerability by analyzing file system operations and configuration changes. A practitioner using Casky would observe findings related to unauthorized file writes outside expected directories, suspicious conf.json modifications in unusual paths, and anomalous endpoint requests to setNotebookIcon with path traversal indicators. By correlating these behavioral signals across Casky's 754 mapped security skills, the platform would surface indicators consistent with Abuse of Elevation/Privilege (T1548) and Lateral Movement techniques, alerting defenders to potential post-exploitation activity that could follow successful exploitation of this path traversal flaw.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-100638. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation