PT-2026-76597 · Siyuan · Siyuan
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SiYuan kernel versions prior to 3.7.4
Description
A path traversal issue exists in the database clean MCP tool. The tool only performs an empty-string check on the
id parameter before passing it to the RemoveUnusedAttributeView() function, which constructs a filesystem path using filepath.Join without verifying that the id follows the required node-ID format. An authenticated MCP client can use path traversal sequences in the id parameter to force the kernel to copy any file readable by the process into the history directory and subsequently delete the original file.Recommendations
Update to version 3.7.4 or later.
As a temporary mitigation, restrict access to the database clean MCP tool or avoid using the
id parameter until the update is applied.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan