mediumCVSS 5.7Vulnerability

GHSA-p23f-cm6q-2qp8

# Security Advisory — SiYuan MCP `asset.upload` Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass) | Field | Value | |---|---| | **Disclosed by** | joysinleung (`[email protected]`) | | **Report date** | 2026-08-13 | | **Product** | SiYuan (思源笔记) — `siyuan-note/siyuan` | | **Go module** | `github.com/siyuan-note/siyuan/kernel` | | **Affected versions** | `<= 3.8.0` (latest release at report time; statically confirmed on v3.8.0) | | **Patched versions** | 3.8.1 | | **Component** | `kernel/mcp/tools/asset.go` (`assetUpload`), `kernel/model/upload.go` (`InsertLocalAssets`) | | **Relationship to prior advisory** | **Residual of CVE-2026-66012** (GHSA-cvhv-7xhj-xjp8) MCP remediation. See §Relationship. | | **EPSS (exploitation probability)** | Low. Requires the AI Agent to invoke `asset.upload` and the user to approve the (category-level) confirmation; reachable via prompt-injection of the agent. | | **KEV (CISA Known Exploited)** | No (not listed in CISA KEV at report time). | | **Default-config reachable** | **Partial** — requires the Agent/MCP surface to be configured (admin) and a user approval click; the boundary check itself is entirely absent, so any approved upload reads outside the workspace. | --- ## Summary SiYuan exposes a native MCP tool `asset` → `asset.upload`. Its `files` argument is documented as a **comma-separated list of absolute file paths**. The handler (`kernel/mcp/tools/asset.go:195`) only normalizes each entry with `filepath.Abs(...)` — it performs **no workspace boundary check** (`IsSubPath`) and **no sensitive-path check** (`IsSensitivePath`). The downstream `model.InsertLocalAssets` (`kernel/model/upload.go:97`) then `os.Open`s each path and copies its bytes into the workspace `assets/` directory. Every other AI-plane file primitive in SiYuan is workspace-constrained: - `file` / `unzip` tools resolve paths via `resolvePath` (workspace-relative, escape-proof). `asset.upload` is the **only** AI tool that accepts arbitrary

Properties

severity
medium
summary
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)
cvss_score
5.7
retrieved_at
2026-10-03T18:15:00+00:00
ghsa_published
2026-10-02T23:16:56Z
source_url
https://github.com/advisories/GHSA-p23f-cm6q-2qp8
ghsa_updated
2026-10-02T23:17:27Z
ghsa_id
GHSA-p23f-cm6q-2qp8
last_source
GitHub Advisory Database
cve_id
GHSA-p23f-cm6q-2qp8
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
signal_observed_at
2026-10-03T01:59:23+00:00
is_ghsa_only
true

Related Entities (4)

VULNERABLE_TO (1)

←[Software]go/github.com/siyuan-note/siyuan/kernel

AFFECTS (1)

→[Software]go/github.com/siyuan-note/siyuan/kernel

HAS_WEAKNESS (1)

→[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph