Insecure File Access in SiYuan by SiYuan, Inc.
CVE-2026-60083
6.9MEDIUM
What is CVE-2026-60083?
The SiYuan application prior to version 3.8.0 exhibits an incomplete path blocklist in its MCP file tool, resulting in insufficient access controls for sensitive workspace files. This vulnerability allows authenticated administrators to access plaintext publishing passwords stored in 'data/.siyuan/publishAccess.json', as well as other sensitive configuration files like 'data/templates' and 'data/snippets/conf.json'. The lack of proper restrictions places sensitive user data at risk, highlighting the need for immediate remediation.
Affected Version(s)
siyuan 0 < 3.8.0
siyuan 3.8.0
