PT-2026-99304 · Siyuan · Siyuan

·

CVE-2026-100633

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SiYuan versions 3.8.0 through 3.8.3
Description An authenticated administrator using the in-app Agent or the external MCP server can bypass the protected-workspace-file denylist. This occurs because the sensitive-path guard util.IsForbiddenAbsPath() (invoked from resolvePath()) is applied only to the allowed root of recursive operations and not to each resolved descendant path. Consequently, file.grep can return matching lines from non-hidden protected descendants such as conf/conf.json, TLS keys, data/snippets/conf.json, data/templates/, data/.siyuan/publishAccess.json, notebook .siyuan internals, or the kernel log. Additionally, file.copy can copy protected descendants to an ordinary path for retrieval via file.read, and unzip can overwrite protected descendants using ordinary, lexically contained ZIP member names. Since file.grep is classified as a safe action, it requires no per-call confirmation, and confirmation cards for file.copy and unzip only display the allowed root arguments.
Recommendations Update to version 3.8.4.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100633
GHSA-9G6V-R3XF-673Q

Affected Products

Siyuan