PT-2026-83085 · Siyuan · Siyuan
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SiYuan versions prior to 3.8.1
Description
A path traversal issue exists in the
asset.upload MCP tool, which allows the use of arbitrary absolute file paths because it lacks workspace boundary validation. Through prompt injection, an attacker can trick the AI Agent into uploading sensitive files, such as SSH keys or credentials, from locations outside the workspace into the asset directory.Recommendations
Update to version 3.8.1 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan