SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to sensitive workspace files protected by the HTTP API. Authenticated administrators can read plaintext publish-mode passwords from data/.siyuan/publishAccess.json and access other sensitive files like data/templates and data/snippets/conf.json.
Metrics
Affected Vendors & Products
References
History
Mon, 24 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 23 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siyuan
Siyuan siyuan |
|
| Vendors & Products |
Siyuan
Siyuan siyuan |
Sat, 22 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to sensitive workspace files protected by the HTTP API. Authenticated administrators can read plaintext publish-mode passwords from data/.siyuan/publishAccess.json and access other sensitive files like data/templates and data/snippets/conf.json. | |
| Title | SiYuan before v3.8.0 Incomplete Path Blocklist via MCP file tool | |
| First Time appeared |
B3log
B3log siyuan |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:* | |
| Vendors & Products |
B3log
B3log siyuan |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-08-22T12:26:36.709Z
Updated: 2026-08-24T18:41:00.990Z
Reserved: 2026-07-08T12:14:28.344Z
Link: CVE-2026-60083
Updated: 2026-08-24T18:40:54.336Z
Status : Deferred
Published: 2026-08-22T13:16:39.263
Modified: 2026-08-26T17:10:09.810
Link: CVE-2026-60083
No data.