GHSA-P23F-CM6Q-2QP8: GHSA-P23F-CM6Q-2QP8: Workspace Boundary Bypass and Arbitrary File Leak in SiYuan MCP
GHSA-P23F-CM6Q-2QP8: Workspace Boundary Bypass and Arbitrary File Leak in SiYuan MCP Vulnerability ID: GHSA-P23F-CM6Q-2QP8 CVSS Score: 8.6 Published: 2026-10-02 SiYuan is an open-source personal knowledge management
GHSA-P23F-CM6Q-2QP8: Workspace Boundary Bypass and Arbitrary File Leak in SiYuan MCP
Vulnerability ID: GHSA-P23F-CM6Q-2QP8
CVSS Score: 8.6
Published: 2026-10-02
SiYuan is an open-source personal knowledge management system. Its Model Context Protocol (MCP) implementation within the asset.upload tool contains a path-traversal and workspace boundary bypass flaw. This allows remote AI modelsβacting on behalf of attackers via malicious prompts or documentsβto import and read sensitive host-system files, such as private keys and system configurations, through absolute path inputs.
TL;DR
The SiYuan Model Context Protocol (MCP) asset.upload tool failed to restrict file import targets to the designated workspace boundary. Under prompt injection or document coercion, an AI agent could be forced to upload host-system files (like SSH private keys or system configurations) into the public workspace, exposing them to attackers.
β οΈ Exploit Status: POC
Technical Details
- CWE ID: CWE-22 (Improper Limitation of a Pathname to a Restricted Directory)
- Attack Vector: Network (with User Interaction)
- CVSS v3.1 Score: 8.6 (High)
- Exploit Status: Proof-of-Concept
- CISA KEV Status: Not Listed
- Ransomware Association: None
Affected Systems
- SiYuan personal knowledge management system running on Linux, macOS, or Windows host systems.
-
SiYuan: < v3.8.1 (Fixed in:
v3.8.1)
Code Analysis
Commit: b26a4a3
Add path validation for asset upload tool under Model Context Protocol (MCP) handler to prevent arbitrary system asset retrieval.
Mitigation Strategies
- Restrict the SiYuan host process execution environment using system-level containerization.
- Configure operating system permissions to restrict read access to external host files.
- Validate file path parameters in custom integrations by resolving symbolic links before verification.
Remediation Steps:
- Update SiYuan to version v3.8.1 or later to apply the path verification patch.
- Isolate the application process within a containerized environment.
- Restrict read and write access to directories containing sensitive files (such as ~/.ssh and /etc).
References
- GitHub Security Advisory GHSA-p23f-cm6q-2qp8
- SiYuan File Validation Fix Commit
- SiYuan Release Version v3.8.1
Read the full report for GHSA-P23F-CM6Q-2QP8 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.