Siyuan · Siyuan · CVE-2026-82233
**Name of the Vulnerable Software and Affected Versions**
SiYuan versions prior to 3.8.1
**Description**
A path traversal issue exists in the `asset.upload` MCP tool, which allows the use of arbitrary absolute file paths because it lacks workspace boundary validation. Through prompt injection, an attacker can trick the AI Agent into uploading sensitive files, such as SSH keys or credentials, from locations outside the workspace into the asset directory.
**Recommendations**
Update to version 3.8.1 or later.