CyberRota Analysis
AI-GeneratedSiYuan versions prior to 3.8.2 are vulnerable to a path guard bypass in the MCP file-access handler, allowing attackers to exploit case-sensitive file matching on Linux filesystems. This vulnerability enables unauthorized access to the sensitive publishAccess.json file, potentially exposing critical publish-access configurations and metadata. Organizations using affected versions should prioritize patching to mitigate the risk of sensitive data disclosure.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems. Attackers can read the protected publishAccess.json file by requesting case-variant paths like PublishAccess.json to disclose sensitive publish-access configuration and metadata.