MediumVulnerability
GHSA-p23f-cm6q-2qp8: SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)
- Identifier
- GHSA-p23f-cm6q-2qp8
- Published
- Record updated
Summary
SiYuan's MCP tool `asset.upload` accepts a comma-separated `files` list of absolute paths and performs no workspace boundary or sensitive-path check before `model.InsertLocalAssets` opens each file and copies it into the workspace `assets/` directory. An attacker who can steer the AI Agent through prompt injection could make it upload files such as `~/.ssh/id_rsa` into the workspace, where they become reachable. Affected versions are `<= 3.8.0`, and the issue is a residual gap from the remediation of CVE-2026-66012.
Mitigation
Fixed in 3.8.1.
Topics
Related items
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- MediumGHSA-hmq2-7hp6-7crh: Banks: User-controlled prompt input can be parsed as privileged chat messagesSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database
- Medium'AgentCorruption' Puts AWS Environments At Risk With Single PromptSimilar attack · Dark Reading
- MediumGHSA-4xxv-6wmf-xf45: PraisonAI: FastContext path resolution permits absolute and traversal reads outside the workspaceSimilar attack · GitHub Advisory Database