思源笔记(SiYuan)是一款自托管的个人知识管理系统。在 3.8.0 至 3.8.3 版本中,MCP 文件工具中的敏感路径防护机制(util.IsForbiddenAbsPath(),由 resolvePath() 调用)仅对递归操作的允许根目录生效,而未对每个解析出的子路径进行检查——这是针对 GHSA-c8r8-95hg-mp34 的修复不彻底。 因此,经身份验证的管理员可以通过应用内代理(Agent)或外部 MCP 服务器绕过受保护工作区文件的拒绝列表: 可从非隐藏的受保护子路径(例如 conf/conf.
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 3.8.0 ~ 3.8.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100639 | 8.8 HIGH | SiYuan before v3.8.4 Cross-Site Scripting via Kramdown IAL |
| CVE-2026-100646 | 8.1 HIGH | SiYuan before v3.8.4 Authentication Bypass via Missing Origin Header |
| CVE-2026-100645 | 8.0 HIGH | SiYuan 3.7.0 before 3.8.4 Stored XSS via Gallery Kanban |
| CVE-2026-100643 | 8.0 HIGH | SiYuan before v3.8.4 Stored XSS via Attribute View textarea |
| CVE-2026-100641 | 8.0 HIGH | SiYuan before v3.8.4 Stored XSS via Unescaped Flashcard Content |
| CVE-2026-100642 | 7.6 HIGH | SiYuan v2.1.0 before v3.8.4 Cross-Site Request Forgery via CheckAuth |
| CVE-2026-100637 | 7.6 HIGH | SiYuan before v3.8.4 Path Traversal via checkoutRepo sessionID |
| CVE-2026-100638 | 7.6 HIGH | SiYuan before v3.8.4 Path Traversal via setNotebookIcon |
| CVE-2026-100636 | 7.6 HIGH | SiYuan before v3.8.4 Path Traversal via exportBrowserHTML folder |
| CVE-2026-100644 | 7.5 HIGH | SiYuan before v3.8.4 SQL Injection via dailyNoteSavePath |
| CVE-2026-100635 | 5.9 MEDIUM | SiYuan before v3.8.4 Authentication Bypass via Plaintext Session Cookie |
| CVE-2026-100634 | 4.7 MEDIUM | SiYuan before v3.8.4 Missing Authorization via siyuan-send-windows |
| CVE-2026-100640 | 4.7 MEDIUM | SiYuan before v3.8.4 Clipboard Data Disclosure via IPC |
No comments yet