mediumCVSS 4.9Vulnerability

GHSA-3cm4-ccvw-6xr6

### Summary `GHSA-c8r8-95hg-mp34` added a centralized guard, `util.IsForbiddenAbsPath()`, specifically to block access to a small set of sensitive files: `conf/conf.json` (plaintext `accessAuthCode`/API token/cookie key), `data/snippets/conf.json`, the entire `data/templates/` directory, and `data/.siyuan/publishAccess.json` (plaintext publish-mode passwords). It was applied to `kernel/api/file.go` and `kernel/mcp/tools/file.go`. Two other routes in the same server that serve arbitrary files by path, `/history/*path` and `/repo/diff/*path`, construct their target paths independently and were not updated to call this new guard. Since the repo/history snapshot system's tracked root is `data/` (confirmed by `getSyncIgnoreLines()`, whose ignore file lives at `data/.siyuan/syncignore` with entries relative to `data/`), both `data/.siyuan/publishAccess.json` and `data/templates/*` fall within the scope that can legitimately be captured in historical snapshots, meaning a prior version of either file can exist in `util.HistoryDir`/the repo-diff temp checkout even after the live file has been protected by the new guard. This is CWE-862 (Missing Authorization) applied to a very recently introduced protection mechanism. ### Details `kernel/server/serve.go`, `/history/*path` (around line 994): ```go ginServer.GET("/history/*path", model.CheckAuth, model.CheckAdminRole, func(context *gin.Context) { p := filepath.Join(util.HistoryDir, context.Param("path")) // 加密笔记本的历史是密文(.sy/assets/AV),需先解密再输出 if serveEncryptedHistory(context, p) { return } secureAssetContentHeaders(context, p, p) http.ServeFile(context.Writer, context.Request, p) }) ``` No call to `util.IsForbiddenAbsPath(p)` anywhere in this handler. `kernel/server/serve.go`, `/repo/diff/*path` (around line 1241): ```go ginServer.GET("/repo/diff/*path", model.CheckAuth, model.CheckAdminRole, func(context *gin.Context) { requestPath := filepath.Clean(context.Param("path")) if strings.Co

Properties

severity
medium
summary
SiYuan: /history/*path and /repo/diff/*path potentially exposing historical snapshots of data/.siyuan/publishAccess.json and data/templates/*
cvss_score
4.9
retrieved_at
2026-10-05T18:53:05+00:00
ghsa_published
2026-10-05T17:32:44Z
source_url
https://github.com/advisories/GHSA-3cm4-ccvw-6xr6
ghsa_updated
2026-10-05T17:32:45Z
ghsa_id
GHSA-3cm4-ccvw-6xr6
last_source
GitHub Advisory Database
cve_id
GHSA-3cm4-ccvw-6xr6
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
signal_observed_at
2026-10-05T18:46:34+00:00
is_ghsa_only
true

Related Entities (5)

VULNERABLE_TO (1)

←[Software]go/github.com/siyuan-note/siyuan/kernel

AFFECTS (1)

→[Software]go/github.com/siyuan-note/siyuan/kernel

HAS_WEAKNESS (2)

→[Weakness]Missing Authorization
→[Weakness]Exposure of Sensitive Information to an Unauthorized Actor

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-3cm4-ccvw-6xr6 (CVSS 4.9) — Ninja Signal Threat Intelligence | Ninja Signal