Junglewise Threat Intelligence

CVE-2026-85580: SiYuan path guard bypass in MCP file-access handler

CVE-2026-85580 · Severity: medium · CVSS 6.5 · Published 2026-09-04

Technologies: SiYuan. Vendors: SiYuan.

Executive brief

SiYuan is a note-taking and knowledge-management application. On Linux systems, a vulnerability in the file-access handler allows attackers to read sensitive publish-access configuration files by requesting them with different letter casing (e.g., "PublishAccess.json" instead of "publishAccess.json"). This could expose publish visibility settings, password-related metadata, and assist in unauthorized access attempts.

Technical details

The vulnerability is a path traversal / pathname restriction bypass (CWE-22) in SiYuan's MCP (Model Context Protocol) file-access handler on case-sensitive filesystems (Linux). The guard compares paths using case-sensitive matching to protect data/.siyuan/publishAccess.json, but an attacker can bypass this by requesting a case-variant path (e.g., PublishAccess.json) which matches the underlying file on the filesystem while evading the case-sensitive string comparison. A low-privilege or unauthenticated MCP caller can exploit this to read sensitive publish-access metadata without authentication or user interaction. The vulnerability is patched in version v3.8.2 by canonicalizing paths and using platform-appropriate case semantics for comparison.

Affected products

  • SiYuan SiYuan before v3.8.2

Timeline

  • 2026-08-21: disclosed: GitHub Security Advisory GHSA-mmgw-3mx9-cfwp published
  • 2026-09-04: advisory: CVE-2026-85580 published on NVD
  • 2026-09-04: patched: Fix available in v3.8.2

References

Related threats