SiYuan 在 v3.8.1 之前的版本中,其 asset.upload MCP 工具存在路径遍历漏洞,该工具接受任意的绝对文件路径,而未进行工作区边界校验。攻击者可通过提示词注入(prompt injection)诱导 AI Agent 将工作区之外的敏感文件(如 SSH 密钥或凭据)上传到资产目录中。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.8.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet