What happened
NVD/GitHub advisory (GHSA-9g6v-r3xf-673q, CVSS 6.5, published 2026-09-26) documents the incomplete sensitive-path enforcement in SiYuan's MCP file tool.
Why it matters
MCP-driven file tools are the standard agentic file primitive; a partial path guard is a data-exposure bug for self-hosted PKM/agent setups, letting an agent read/write outside its allowed root during recursive operations. Upgrade to the fixed SiYuan release.
Attack vector
In recursive file operations, util.IsForbiddenAbsPath() is only checked against the allowed root; each resolved descendant path is not re-validated, so an MCP tool call can walk from an allowed directory into a sensitive absolute path the config intended to block.
Mitigation
Upgrade SiYuan to the patched version that validates each resolved descendant path; advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-9g6v-r3xf-673q