Sensitive-Path Guard Bypass in SiYuan Personal Knowledge Management System
CVE-2026-100633
8.5HIGH
What is CVE-2026-100633?
SiYuan, a self-hosted personal knowledge management system, has a vulnerability in versions 3.8.0 through 3.8.3 that affects the sensitive-path guard due to an incomplete fix. The MCP file tool allows an authenticated administrator to bypass the protected-workspace-file denylist during recursive operations. This flaw can permit exposure of sensitive files, enabling commands like file.grep, file.copy, and unzip to interact with protected pathways without adequate safeguarding. The issue has been addressed in version 3.8.4.
Affected Version(s)
siyuan 3.8.0 < 3.8.4
siyuan 3.8.4
