A vulnerability was found in SiYuan up to 3.6.1 and classified as critical. This issue affects some unknown processing of the file /api/file/readDir. The manipulation results in out-of-bounds read.
This vulnerability is reported as CVE-2026-33669. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.