Vulnerability  ·  2026-09-27

SiYuan MCP file tool: sensitive-path guard applied only to the root, not descendants (CVE-2026-100633)

VulnerabilityMedium impactGlobalCVE-2026-100633
NVD/GitHub advisory (GHSA-9g6v-r3xf-673q, CVSS 6.5, published 2026-09-26) documents the incomplete sensitive-path enforcement in SiYuan's MCP file tool.
MCP-driven file tools are the standard agentic file primitive; a partial path guard is a data-exposure bug for self-hosted PKM/agent setups, letting an agent read/write outside its allowed root during recursive operations. Upgrade to the fixed SiYuan release.
In recursive file operations, util.IsForbiddenAbsPath() is only checked against the allowed root; each resolved descendant path is not re-validated, so an MCP tool call can walk from an allowed directory into a sensitive absolute path the config intended to block.
Upgrade SiYuan to the patched version that validates each resolved descendant path; advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-9g6v-r3xf-673q
NVD - CVE-2026-100633
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →