GHSA-3cm4-ccvw-6xr6
### Summary `GHSA-c8r8-95hg-mp34` added a centralized guard, `util.IsForbiddenAbsPath()`, specifically to block access to a small set of sensitive files: `conf/conf.json` (plaintext `accessAuthCode`/API token/cookie key), `data/snippets/conf.json`, the entire `data/templates/` directory, and `data/.siyuan/publishAccess.json` (plaintext publish-mode passwords). It was applied to `kernel/api/file.go` and `kernel/mcp/tools/file.go`. Two other routes in the same server that serve arbitrary files by path, `/history/*path` and `/repo/diff/*path`, construct their target paths independently and were not updated to call this new guard. Since the repo/history snapshot system's tracked root is `data/` (confirmed by `getSyncIgnoreLines()`, whose ignore file lives at `data/.siyuan/syncignore` with entries relative to `data/`), both `data/.siyuan/publishAccess.json` and `data/templates/*` fall within the scope that can legitimately be captured in historical snapshots, meaning a prior version of either file can exist in `util.HistoryDir`/the repo-diff temp checkout even after the live file has been protected by the new guard. This is CWE-862 (Missing Authorization) applied to a very recently introduced protection mechanism. ### Details `kernel/server/serve.go`, `/history/*path` (around line 994): ```go ginServer.GET("/history/*path", model.CheckAuth, model.CheckAdminRole, func(context *gin.Context) { p := filepath.Join(util.HistoryDir, context.Param("path")) // 加密笔记本的历史是密文(.sy/assets/AV),需先解密再输出 if serveEncryptedHistory(context, p) { return } secureAssetContentHeaders(context, p, p) http.ServeFile(context.Writer, context.Request, p) }) ``` No call to `util.IsForbiddenAbsPath(p)` anywhere in this handler. `kernel/server/serve.go`, `/repo/diff/*path` (around line 1241): ```go ginServer.GET("/repo/diff/*path", model.CheckAuth, model.CheckAdminRole, func(context *gin.Context) { requestPath := filepath.Clean(context.Param("path")) if strings.Co
Properties
- severity
- medium
- summary
- SiYuan: /history/*path and /repo/diff/*path potentially exposing historical snapshots of data/.siyuan/publishAccess.json and data/templates/*
- cvss_score
- 4.9
- retrieved_at
- 2026-10-05T18:53:05+00:00
- ghsa_published
- 2026-10-05T17:32:44Z
- source_url
- https://github.com/advisories/GHSA-3cm4-ccvw-6xr6
- ghsa_updated
- 2026-10-05T17:32:45Z
- ghsa_id
- GHSA-3cm4-ccvw-6xr6
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-3cm4-ccvw-6xr6
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- signal_observed_at
- 2026-10-05T18:46:34+00:00
- is_ghsa_only
- true
Related Entities (5)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (2)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph