GHSA-4WWP-F6GW-6QM5: GHSA-4WWP-F6GW-6QM5: Sensitive Information Disclosure via Incomplete Path Blocklist in SiYuan
GHSA-4WWP-F6GW-6QM5: Sensitive Information Disclosure via Incomplete Path Blocklist in SiYuan Vulnerability ID: GHSA-4WWP-F6GW-6QM5 CVSS Score: 7.7 Published: 2026-10-05 An incomplete path blocklist in the file retr
GHSA-4WWP-F6GW-6QM5: Sensitive Information Disclosure via Incomplete Path Blocklist in SiYuan
Vulnerability ID: GHSA-4WWP-F6GW-6QM5
CVSS Score: 7.7
Published: 2026-10-05
An incomplete path blocklist in the file retrieval engine of the SiYuan knowledge management platform allows authenticated users to read TLS and CA private key materials directly from the configuration directory.
TL;DR
Authenticated users can bypass the path-guard system in SiYuan versions prior to v3.8.2 to extract raw TLS private keys and CA files, enabling traffic decryption or certificate spoofing.
Technical Details
- CWE ID: CWE-184 (Incomplete List of Disallowed Input Values)
- Attack Vector: Network (Authenticated API call)
- CVSS Score: 7.7
- Exploit Status: poc
- KEV Status: Not Listed
Affected Systems
- SiYuan Knowledge Management Platform
-
SiYuan: < v3.8.2 (Fixed in:
v3.8.2)
Code Analysis
Commit: 256d73a
Fix security vulnerability: restrict direct access to TLS cert and key files in path guard
Mitigation Strategies
- Upgrade the SiYuan application kernel to version v3.8.2 or later to apply the expanded path blocklist check.
- Limit network exposure of the local kernel API endpoint to prevent unauthorized client access.
- Enforce filesystem-level permissions restricting read privileges of the configuration folder to only the running application owner.
Remediation Steps:
- Identify the running version of the SiYuan platform.
- Download and install version v3.8.2 or later from the official repository releases.
- Rotate existing TLS leaf keys and Root CA certificates stored in the 'conf/' workspace directory to neutralize any past key compromises.
References
Read the full report for GHSA-4WWP-F6GW-6QM5 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.