Impact
SiYuan products prior to version 3.8.1 contain a path traversal flaw in the asset.upload functionality of the MCP tool. The tool accepts arbitrary absolute file paths without enforcing workspace boundaries, allowing an adversary to direct the built‑in AI Agent to upload files from outside the intended workspace directory. By injecting specially crafted commands into prompts, an attacker can cause the application to place sensitive files such as SSH keys or credentials into the asset directory, exposing them to the application user and potentially other users who can view the asset repository. The weakness belongs to CWE‑22: Path Traversal.
Affected Systems
The vulnerability affects SiYuan note products. All installations running a version older than 3.8.1 are vulnerable. No specific sub‑versions were listed beyond the v3.8.1 cut‑off.
Risk and Exploitability
The CVSS score of 6.9 categorises the issue as moderate to high severity. No EPSS score is currently available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a lower current exploitation probability. However, because the flaw relies on prompting the AI Agent, an attacker who can control request payloads to the asset.upload endpoint—or that can execute code within the application’s runtime—can exploit it. Successful exploitation would create or overwrite files in a controlled directory, leading to potential information disclosure of sensitive credentials and alike.
OpenCVE Enrichment