思元(SiYuan)v3.8.2 之前的版本存在一个路径防护绕过漏洞,该漏洞存在于 MCP 文件访问处理器中,且在 Linux 文件系统上使用区分大小写的匹配方式。攻击者可以通过请求大小写变体的路径(例如 )来读取受保护的 文件,从而泄露敏感的发布访问配置和元数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| siyuan-note | siyuan | < 3.8.2 |
affected |
3.8.2 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.8.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85584 | 7.5 HIGH | SiYuan before v3.8.2 Denial of Service via Auth Throttle |
| CVE-2026-85581 | 7.5 HIGH | SiYuan before v3.8.2 Denial of Service via unauthenticated UI-process registration |
| CVE-2026-85585 | 7.5 HIGH | SiYuan before v3.8.2 Unbounded Memory Consumption via ControlConcurrency |
| CVE-2026-85578 | 6.5 MEDIUM | SiYuan through 3.8.1 Authorization Bypass via getFile |
| CVE-2026-85583 | 6.5 MEDIUM | SiYuan before v3.8.2 Path Traversal via symlink in file API |
| CVE-2026-85582 | 6.5 MEDIUM | SiYuan before v3.8.2 Unbounded Session Creation via Basic Auth |
| CVE-2026-85579 | 4.3 MEDIUM | SiYuan before v3.8.2 Information Disclosure via undoState |
No comments yet