CVE-2026-82233: SiYuan before v3.8.1 contains a path traversal vulnerability in the asset.upload MCP tool that accepts arbitrary absolut
Summary
SiYuan versions before v3.8.1 have a path traversal vulnerability (a flaw that lets attackers access files outside their intended directory) in the asset.upload tool that doesn't check if file paths are within the workspace boundary. An attacker can use prompt injection (tricking an AI by hiding instructions in its input) to make an AI Agent upload sensitive files like SSH keys or credentials from anywhere on the system into the asset directory.
Solution / Mitigation
Update SiYuan to v3.8.1 or later.
Vulnerability Details
5.7(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
network
low
low
required
August 28, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82233
First tracked: August 28, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 85%