GHSA-3cm4-ccvw-6xr6: Weak Path Access Control and History/Repo-Diff Endpoint Bypass in SiYuan
Vulnerability ID: GHSA-3CM4-CCVW-6XR6
CVSS Score: 7.5
Published: 2026-10-05
A weak path access control vulnerability in SiYuan note-taking application allowed authenticated users to bypass restricted file paths by requesting historical backups and git diffs of sensitive configurations, including plain-text authentication tokens.
TL;DR
Weak relative path checks in SiYuan allowed standard users to access sensitive configuration files and publishing tokens by requesting them via unprotected history and git diff endpoints.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-862 (Missing Authorization) / CWE-22 (Path Traversal)
- Attack Vector: Network (Authenticated Standard User or Local API Access)
- CVSS v3.1: 7.5 (Medium-High)
- Exploit Status: Proof-of-Concept (PoC) Analyzed
- Impact: Information Disclosure (Retrieval of plain-text publishing tokens and templates)
- Remediation: Upgrade to v3.8.1 or higher
Affected Systems
- SiYuan personal knowledge management system
-
SiYuan: < 3.8.1 (Fixed in:
v3.8.1)
Code Analysis
Commit: 035bf9a
Add relative path filters and fix directory traversal inside history and repo-diff controllers
Mitigation Strategies
- Upgrade SiYuan to version v3.8.1 or later.
- Implement network binding constraints to limit API access to localhost.
- Deploy reverse-proxy level URL filtering blocks for sensitive paths.
Remediation Steps:
- Navigate to the official SiYuan release page at https://github.com/siyuan-note/siyuan/releases/tag/v3.8.1.
- Download the verified v3.8.1 binaries corresponding to your environment's operating system.
- Stop the running SiYuan application instance.
- Replace the existing binaries with the updated v3.8.1 version.
- Restart the application and verify path blocks are active by attempting to query
/history/elements containing sensitive paths.
References
Read the full report for GHSA-3CM4-CCVW-6XR6 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)