PT-2026-99304 · Siyuan · Siyuan
CVSS v4.0
8.5
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SiYuan versions 3.8.0 through 3.8.3
Description
An authenticated administrator using the in-app Agent or the external MCP server can bypass the protected-workspace-file denylist. This occurs because the sensitive-path guard
util.IsForbiddenAbsPath() (invoked from resolvePath()) is applied only to the allowed root of recursive operations and not to each resolved descendant path. Consequently, file.grep can return matching lines from non-hidden protected descendants such as conf/conf.json, TLS keys, data/snippets/conf.json, data/templates/, data/.siyuan/publishAccess.json, notebook .siyuan internals, or the kernel log. Additionally, file.copy can copy protected descendants to an ordinary path for retrieval via file.read, and unzip can overwrite protected descendants using ordinary, lexically contained ZIP member names. Since file.grep is classified as a safe action, it requires no per-call confirmation, and confirmation cards for file.copy and unzip only display the allowed root arguments.Recommendations
Update to version 3.8.4.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siyuan