{"data":{"id":"e00e9e77-4884-49ba-aafe-61c443864fd9","title":"GHSA-p23f-cm6q-2qp8: SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)","summary":"SiYuan's MCP tool `asset.upload` accepts a comma-separated `files` list of absolute paths and performs no workspace boundary or sensitive-path check before `model.InsertLocalAssets` opens each file and copies it into the workspace `assets/` directory. An attacker who can steer the AI Agent through prompt injection could make it upload files such as `~/.ssh/id_rsa` into the workspace, where they become reachable. Affected versions are `<= 3.8.0`, and the issue is a residual gap from the remediation of CVE-2026-66012.","solution":"Fixed in 3.8.1.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-p23f-cm6q-2qp8","publishedAt":"2026-10-02T23:16:56.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["prompt_injection"],"issueType":"vulnerability","affectedPackages":["github.com/siyuan-note/siyuan/kernel@< 0.0.0-20260813142104-b26a4a307b8a (fixed: 0.0.0-20260813142104-b26a4a307b8a)"],"affectedPackageNames":["github.com/siyuan-note/siyuan/kernel"],"affectedVendors":[],"affectedVendorsRaw":["SiYuan MCP","SiYuan"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":["GHSA-p23f-cm6q-2qp8"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-10-02T23:16:56.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}