CVE-2026-85580: SiYuan before v3.8.2 Path Guard Bypass via Case Mismatch

Published Sep 4, 2026
·
Updated

SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems. Attackers can read the protected publishAccess.json file by requesting case-variant paths like PublishAccess.json to disclose sensitive publish-access configuration and metadata.

Affected Software

1 affected component
SiYuan SiYuan<3.8.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SiYuan to a version that resolves this vulnerability.

    Fixed in v3.8.2

Event History

Sep 4, 2026
CVE Published
via MITRE·11:29 AM
Data Sourced
via MITRE·11:29 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs low-privileged access to the SiYuan MCP file-access handler and network reachability to the affected service. No user interaction is required.

2

Which deployments are affected?

SiYuan versions before v3.8.2 are affected where the MCP file-access handler runs on a case-sensitive Linux filesystem. The issue results from case-sensitive path matching in the guard.

3

What information could be exposed?

An attacker can request a case-variant filename, such as PublishAccess.json, to read the protected publishAccess.json file. This can disclose sensitive publish-access configuration and metadata.

4

How can I determine whether exposure may have occurred?

Review requests handled by the MCP file-access endpoint for case variants of publishAccess.json, including PublishAccess.json. Successful responses containing publish-access configuration or metadata indicate exposure.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203