github.com/siyuan-note/siyuan/kernel
Go104 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/siyuan-note/siyuan/kernelpage 3 of 3
- CVE-2026-82233MEDIUMCVSS 5.7EG 5.7fixed in 0.0.0-20260813142104-b26a4a307b8a2026-08-28
SiYuan before v3.8.1 contains a path traversal vulnerability in the asset.upload MCP tool that accepts arbitrary absolute file paths without workspace boundary validation. Attackers can induce the AI Agent to upload sensitive files such as…
- CVE-2026-82234HIGHCVSS 8.2EG 8.2fixed in 0.0.0-20260813142806-dd2778b70d022026-08-28
SiYuan versions before v3.8.1 contain a server-side request forgery vulnerability in the http_request and web_fetch agent tools that perform DNS resolution only at guard time without validating the connect-time resolution. Attackers can us…
- CVE-2026-82651MEDIUMCVSS 4.9EG 4.9fixed in 0.0.0-20260816034002-035bf9a8c3112026-08-30
SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*path and /repo/diff/*path endpoints in kernel/server/serve.go. These routes require admin authentication but construct fi…
- CVE-2026-85175HIGHCVSS 8.8EG 8.8fixed in 0.0.0-20260819144130-256d73aa7f942026-09-03
SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), which only blocks conf/conf.json by exact match and does not restrict the TLS private key (conf/ke…
Check whether github.com/siyuan-note/siyuan/kernel is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/siyuan-note/siyuan/kernel CVEs against the assets you own.
Book a Demo →