Insecure File Access in SiYuan by SiYuan, Inc.
CVE-2026-60083

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
22 August 2026

What is CVE-2026-60083?

The SiYuan application prior to version 3.8.0 exhibits an incomplete path blocklist in its MCP file tool, resulting in insufficient access controls for sensitive workspace files. This vulnerability allows authenticated administrators to access plaintext publishing passwords stored in 'data/.siyuan/publishAccess.json', as well as other sensitive configuration files like 'data/templates' and 'data/snippets/conf.json'. The lack of proper restrictions places sensitive user data at risk, highlighting the need for immediate remediation.

Affected Version(s)

siyuan 0 < 3.8.0

siyuan 3.8.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

alham-rizvi
.