Impact
The vulnerability lies in SiYuan's MCP file tool, where the internal path validation guard only checks the root during recursive operations. This deficiency allows an authenticated administrator to bypass the protected‑workspace denylist. Through the file.grep, file.copy, and unzip actions, an attacker can read secret configuration files, TLS keys, and other protected descendants, or overwrite them with malicious content. The result is the unintended disclosure of sensitive data and the potential for further exploitation when privileged secrets are exposed.
Affected Systems
SiYuan, versions 3.8.0 through 3.8.3, are affected. The issue is fixed in version 3.8.4 and later releases.
Risk and Exploitability
CVSS score of 8.5 indicates high severity. EPSS score is unavailable, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires authenticated administrator access to the MCP API or the in‑app Agent. An attacker with these privileges can read or modify critical files. Given the lack of widespread exploitation data, the risk is moderate to high for environments that expose the MCP interface to privileged users. Immediate action to mitigate the risk is recommended.
OpenCVE Enrichment