CVE-2026-85580
SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems. Attackers can read the protected publishAccess.json file by requesting case-variant paths like PublishAccess.json to disclose sensitive publish-access configuration and metadata.
- Published Sep 4, 2026
- CVSS 7.1 high
- 0.6% chance of exploitation in the next 30 days (EPSS)
- A fix is available