Vulnerability GHSA-p23f-cm6q-2qp8
Medium Risk
MEDIUM RISK
CVSS Score: 5.7
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
10 hours ago
October 02, 2026 at 11:16 PM UTC
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)
<0.0.0-20260813142104-b26a4a307b8a
<0.0.0-20260813142104-b26a4a307b8a
Summary
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)
Details
Security Advisory — SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)
| Field | Value |
|---|---|
| Disclosed by | joysinleung ([email protected]) |
| Report date | 2026-08-13 |
| Product | SiYuan (思源笔记) — siyuan-note/siyuan |
| Go module | github.com/siyuan-note/siyuan/kernel |
| Affected versions | <= 3.8.0 (latest release at report time; statically confirmed on v3.8.0) |
| Patched versions | 3.8.1 |
| Component | kernel/mcp/tools/asset.go (assetUpload), kernel/model/upload.go (InsertLocalAssets) |
| Relationship to prior advisory | Residual of CVE-2026-66012 (GHSA-cvhv-7xhj-xjp8) MCP remediation. See §Relationship. |
| EPSS (exploitation probability) | Low. Requires the AI Agent to invoke asset.upload and the user to approve the (category-level) confirmation; reachable via prompt-injection of the agent. |
| KEV (CISA Known Exploited) | No (not listed in CISA KEV at report time). |
| Default-config reachable | Partial — requires the Agent/MCP surface to be configured (admin) and a user approval click; the boundary check itself is entirely absent, so any approved upload reads outside the workspace. |
Appendix: Suggested Patch (F10)
diff --git a/kernel/mcp/tools/asset.go b/kernel/mcp/tools/asset.go
index aaa..bbb 100644
--- a/kernel/mcp/tools/asset.go
+++ b/kernel/mcp/tools/asset.go
@@ -195,8 +195,16 @@ func assetUpload(args map[string]any) (CallToolResult, error) {
fileList := strings.Split(filesStr, ",")
for i, f := range fileList {
abs, err := filepath.Abs(strings.TrimSpace(f))
- if err != nil {
+ if err != nil {
return CallToolResult{}, err
}
+ // 边界校验:仅允许工作区内的资产,拒绝任意绝对路径越界读
+ if !util.IsSubPath(util.WorkspaceDir, abs) || util.IsSensitivePath(abs) {
+ ret.Code = -1
+ ret.Msg = fmt.Sprintf("asset path %s is outside the workspace or sensitive", abs)
+ return CallToolResult{}, fmt.Errorf("asset path outside workspace: %s", abs)
+ }
fileList[i] = abs
}
succMap, err := model.InsertLocalAssets(id, fileList, true)
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
10 hours ago
SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)
<0.0.0-20260813142806-dd2778b70d02 GHSA-x8gv-g2g3-65fj
<0.0.0-20260813142806-dd2778b70d02 GHSA-x8gv-g2g3-65fj
High Risk
10 hours ago
SiYuan: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mode readers
<0.0.0-20260804015139-bd067a4fe9b2 GHSA-4vpg-gwqq-w44c
<0.0.0-20260804015139-bd067a4fe9b2 GHSA-4vpg-gwqq-w44c
Low Risk
10 hours ago
SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass
<0.0.0-20260803045322-cb67e0b4fab5 GHSA-3cc2-h3v6-rqpq
<0.0.0-20260803045322-cb67e0b4fab5 GHSA-3cc2-h3v6-rqpq
Medium Risk
1 day ago
SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block
<0.0.0-20260812083335-251596fc0de2 GHSA-vg99-7gj7-2fr5
<0.0.0-20260812083335-251596fc0de2 GHSA-vg99-7gj7-2fr5
Medium Risk
1 day ago
SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering
<0.0.0-20260812083335-251596fc0de2 GHSA-j4ph-9xwf-wcj4
<0.0.0-20260812083335-251596fc0de2 GHSA-j4ph-9xwf-wcj4
Impacted packages
Timeline
Published
10 hours ago
October 02, 2026 at 11:16 PM UTC
Last Modified
9 hours ago
October 02, 2026 at 11:30 PM UTC