Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rp7c-4prv-9rrg

Опубликовано: 22 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 4.9

Описание

SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to sensitive workspace files protected by the HTTP API. Authenticated administrators can read plaintext publish-mode passwords from data/.siyuan/publishAccess.json and access other sensitive files like data/templates and data/snippets/conf.json.

SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to sensitive workspace files protected by the HTTP API. Authenticated administrators can read plaintext publish-mode passwords from data/.siyuan/publishAccess.json and access other sensitive files like data/templates and data/snippets/conf.json.

EPSS

Процентиль: 33%
0.00391
Низкий

6.9 Medium

CVSS4

4.9 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.9
nvd
3 дня назад

SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to sensitive workspace files protected by the HTTP API. Authenticated administrators can read plaintext publish-mode passwords from data/.siyuan/publishAccess.json and access other sensitive files like data/templates and data/snippets/conf.json.

EPSS

Процентиль: 33%
0.00391
Низкий

6.9 Medium

CVSS4

4.9 Medium

CVSS3

Дефекты

CWE-863