Junglewise Threat Intelligence

CVE-2026-60083: SiYuan MCP file tool incomplete path blocklist

CVE-2026-60083 · Severity: medium · CVSS 4.9 · Published 2026-08-22

Technologies: SiYuan. Vendors: SiYuan.

Executive brief

SiYuan is a note-taking and knowledge management application. A flaw in its MCP (Model Context Protocol) file tool fails to restrict access to sensitive workspace files that are protected by the HTTP API, including plaintext passwords used to secure shared notebooks. An authenticated administrator can exploit this to read password-protected publish-mode sharing credentials and other sensitive configuration files.

Technical details

The vulnerability is an incomplete authorization blocklist (CWE-863) in the MCP file tool's resolvePath() function. The function implements only 1 of 4 sensitive-path blocks enforced by the HTTP API's refuseToAccess() function: conf/conf.json is blocked, but data/snippets/conf.json, the entire data/templates directory, and data/.siyuan/publishAccess.json are not. An authenticated administrator-level MCP client can invoke the tool's list, read, grep, and find actions against these unblocked paths to retrieve sensitive data, specifically plaintext publish-mode passwords that protect shared notebooks. The attack requires prior authentication at the administrator level with network access to the MCP endpoint. Patched in version 3.8.0.

Affected products

  • SiYuan SiYuan before 3.8.0

Timeline

  • 2026-08-08: disclosed
  • 2026-08-22: advisory
  • 2026-08-22: patched: v3.8.0

References

Related threats