Vulnerability  ·  2026-08-24

SiYuan MCP file tool — incomplete path blocklist exposes publish-mode passwords and sensitive workspace files

VulnerabilityMedium impactGlobalCVE-2026-60083
SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to sensitive workspace files that are otherwise protected by the HTTP API, allowing authenticated administrators (and potentially MCP clients with equivalent access) to read plaintext publish-mode passwords and other protected files.
Demonstrates that MCP tool authorization boundaries frequently do not mirror an application's own HTTP API access controls, creating a bypass path where the MCP surface is less restrictive than the primary application interface it wraps.
An MCP client with file-tool access uses paths that evade the incomplete path blocklist to read files that should be restricted by the HTTP API, including data/.siyuan/publishAccess.json which stores plaintext publish-mode passwords.
SiYuan before v3.8.0 (MCP file tool)
Upgrade to SiYuan v3.8.0 or later; audit MCP file-tool path restrictions; rotate any publish-mode passwords that may have been exposed.
NVD - CVE-2026-60083SiYuan Security Advisory GHSA-c8r8-95hg-mp34
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →