Vulnerability GHSA-4wwp-f6gw-6qm5

Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
7 hours ago
October 05, 2026 at 05:32 PM UTC
SiYuan: TLS Private Keys Readable via getFile (Incomplete Blocklist)
<0.0.0-20260819144130-256d73aa7f94
<0.0.0-20260819144130-256d73aa7f94

Summary

SiYuan: TLS Private Keys Readable via getFile (Incomplete Blocklist)

Details

Summary:

IsForbiddenAbsPath() only blocks conf/conf.json by exact match. The TLS private key (conf/key.pem) and CA private key (conf/ca.key) live in the same conf/ directory and are absent from the blocklist. Any authenticated user can retrieve them via POST /api/file/getFile.

Root cause

kernel/util/path_guard.go, IsForbiddenAbsPath() has no entry for TLS key material. The getFile handler at kernel/api/file.go:497 skips the blocklist for RoleAdministrator, and in v3.8.1 all authenticated users receive RoleAdministrator (no non-admin role is currently issued to direct API consumers). The files are generated on every boot regardless of whether TLS is active.

Steps to reproduce:

# No token required on a default no-auth-code instance
curl -s -X POST http://TARGET:6806/api/file/getFile \
  -H "Content-Type: application/json" \
  -d '{"path": "/conf/key.pem"}'
curl -s -X POST http://TARGET:6806/api/file/getFile \
  -H "Content-Type: application/json" \
  -d '{"path": "/conf/ca.key"}'

Response: Raw PEM private key bytes.

2026-08-19_14-19

Impact:

On deployments with TLS enabled (--ssl flag or NetworkServeTLS), possession of key.pem allows decryption of captured HTTPS traffic. Possession of ca.key allows signing certificates trusted by any client that imported SiYuan's locaprompts users to do). The files exist on every installation even whenTLS is currently inactive.

Prior art:

This is the same class of bug as GHSA-9jfx-rc58-h23j (conf.json readable via template render) and GHSA-c8r8-95hg-mp34 (MCP file tool blocklist incomplete). The fix is to add conf/key.pem, conf/ca.key, conf/cert.pem, and conf/ca.crt to IsForbiddenAbsPath().

Timeline

Published
7 hours ago
October 05, 2026 at 05:32 PM UTC
Last Modified
7 hours ago
October 05, 2026 at 05:45 PM UTC