Vulnerability GHSA-p23f-cm6q-2qp8

Medium Risk
MEDIUM RISK
CVSS Score: 5.7
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
10 hours ago
October 02, 2026 at 11:16 PM UTC
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)
<0.0.0-20260813142104-b26a4a307b8a
<0.0.0-20260813142104-b26a4a307b8a

Summary

SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)

Details

Security Advisory — SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)

Field Value
Disclosed by joysinleung ([email protected])
Report date 2026-08-13
Product SiYuan (思源笔记) — siyuan-note/siyuan
Go module github.com/siyuan-note/siyuan/kernel
Affected versions <= 3.8.0 (latest release at report time; statically confirmed on v3.8.0)
Patched versions 3.8.1
Component kernel/mcp/tools/asset.go (assetUpload), kernel/model/upload.go (InsertLocalAssets)
Relationship to prior advisory Residual of CVE-2026-66012 (GHSA-cvhv-7xhj-xjp8) MCP remediation. See §Relationship.
EPSS (exploitation probability) Low. Requires the AI Agent to invoke asset.upload and the user to approve the (category-level) confirmation; reachable via prompt-injection of the agent.
KEV (CISA Known Exploited) No (not listed in CISA KEV at report time).
Default-config reachable Partial — requires the Agent/MCP surface to be configured (admin) and a user approval click; the boundary check itself is entirely absent, so any approved upload reads outside the workspace.

Appendix: Suggested Patch (F10)

diff --git a/kernel/mcp/tools/asset.go b/kernel/mcp/tools/asset.go
index aaa..bbb 100644
--- a/kernel/mcp/tools/asset.go
+++ b/kernel/mcp/tools/asset.go
@@ -195,8 +195,16 @@ func assetUpload(args map[string]any) (CallToolResult, error) {
 	fileList := strings.Split(filesStr, ",")
 	for i, f := range fileList {
 		abs, err := filepath.Abs(strings.TrimSpace(f))
-		if err != nil {
+		if err != nil {
 			return CallToolResult{}, err
 		}
+		// 边界校验:仅允许工作区内的资产,拒绝任意绝对路径越界读
+		if !util.IsSubPath(util.WorkspaceDir, abs) || util.IsSensitivePath(abs) {
+			ret.Code = -1
+			ret.Msg = fmt.Sprintf("asset path %s is outside the workspace or sensitive", abs)
+			return CallToolResult{}, fmt.Errorf("asset path outside workspace: %s", abs)
+		}
 		fileList[i] = abs
 	}
 	succMap, err := model.InsertLocalAssets(id, fileList, true)

Timeline

Published
10 hours ago
October 02, 2026 at 11:16 PM UTC
Last Modified
9 hours ago
October 02, 2026 at 11:30 PM UTC