Siyuan · Siyuan · CVE-2026-100633
**Name of the Vulnerable Software and Affected Versions**
SiYuan versions 3.8.0 through 3.8.3
**Description**
An authenticated administrator using the in-app Agent or the external MCP server can bypass the protected-workspace-file denylist. This occurs because the sensitive-path guard `util.IsForbiddenAbsPath()` (invoked from `resolvePath()`) is applied only to the allowed root of recursive operations and not to each resolved descendant path. Consequently, `file.grep` can return matching lines from non-hidden protected descendants such as `conf/conf.json`, TLS keys, `data/snippets/conf.json`, `data/templates/`, `data/.siyuan/publishAccess.json`, notebook `.siyuan` internals, or the kernel log. Additionally, `file.copy` can copy protected descendants to an ordinary path for retrieval via `file.read`, and `unzip` can overwrite protected descendants using ordinary, lexically contained ZIP member names. Since `file.grep` is classified as a safe action, it requires no per-call confirmation, and confirmation cards for `file.copy` and `unzip` only display the allowed root arguments.
**Recommendations**
Update to version 3.8.4.