{"id":"CVE-2026-65607","aliases":["GHSA-gw25-m53r-qh88"],"title":"SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)","summary":"SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","vendor":"siyuan-note","product":"github.com/siyuan-note/siyuan/kernel","ecosystem":"go","affected":["github.com/siyuan-note/siyuan/kernel < 0.0.0-20260510110132-b763d787d1f2"],"patched":["github.com/siyuan-note/siyuan/kernel 0.0.0-20260510110132-b763d787d1f2"],"published":"2026-09-03","updated":"2026-09-03","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-gw25-m53r-qh88","references":[{"url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-gw25-m53r-qh88"},{"url":"https://github.com/siyuan-note/siyuan/commit/b763d787d1f2b862c577049e4ee147c5857fe413"},{"url":"https://github.com/siyuan-note/siyuan"}],"tags":["osv","go"],"epss":0.00586,"epssPercentile":0.46453,"ingestedAt":"2026-09-03T19:32:13.601Z","slug":"CVE-2026-65607","body":"## Overview\n\n## Summary\nSiYuan's `/export/` file handler was hardened against export disclosure (issue #12213) by adding an\n`IsSubPath(exportBaseDir, fullPath)` check and an `IsSensitivePath()` check in commit `bb481e1`. These guards\nwere added only to the main branch of the handler. The handler begins with a short-circuit branch:\n```go\nif strings.HasPrefix(c.Request.URL.Path, \"/export/temp/\") {\n    c.File(filepath.Join(util.TempDir, c.Request.URL.Path))\n    return\n}\n```\nThis branch joins the **broader** `util.TempDir` with the raw, percent-decoded request path and serves it with\n**neither** `IsSubPath` **nor** `IsSensitivePath`. An authenticated request to\n`/export/temp/%2e%2e/.../etc/passwd` traverses out of `TempDir` and reads arbitrary files - exactly the\nsensitive-file disclosure the patch intended to prevent. Present in the latest master.\n\n## Affected\n- From commit `bb481e1` (the hardening) through the latest master.\n- Requires SiYuan access authorization (`model.CheckAuth`) - but the patch's stated goal is to deny sensitive-file\n  export even to authorized callers.\n\n## Root cause\n`kernel/server/serve.go` `serveExport()`: the main branch has `IsSubPath` + `IsSensitivePath`; the\n`/export/temp/` short-circuit branch (above it) has neither and uses `util.TempDir` as its root.\n`c.Request.URL.Path` is percent-decoded by net/http, so `%2e%2e` becomes `..` and `filepath.Join` collapses it.\n\n## Incomplete-fix lineage\n- Export disclosure (issue #12213; CVE-2026-30869) -> fix `bb481e1` / `d68bd5a` (GHSA-6865-qjcf-286f): guards on\n  the main branch + `IsSensitivePath` extended to `*.db`/`*.log`.\n- Follow-up CVE-2026-41894 (GHSA-hjh7-r5w8-5872) in the same `/export` path family.\n- The `/export/temp/` short-circuit branch was never covered by the guards (this report).\n\n## Proof of concept (benign)\n1. Authenticate (access auth code).\n2. `GET /export/<sensitive>` (main branch) -> 401/403 (guards work).\n3. `GET /export/temp/%2e%2e/%2e%2e/.../tmp/<planted-marker>` (or `/etc/hostname`) -> 200 + file content,\n   demonstrating the unguarded traversal. The PoC reads only a planted marker / `/etc/hostname`; no credentials.\n\n## Impact\nAuthenticated arbitrary file read bypassing the sensitive-file protection: `/etc/passwd`, `~/.ssh/*`, SiYuan\n`*.db` workspace data, `*.log`. \n\n## Remediation\n- Apply `IsSubPath` + `IsSensitivePath` to the `/export/temp/` branch (or restrict its root to `TempDir/temp` with\n  an `IsSubPath` check).\n- `filepath.Clean` the request path and reject `..`.\n- Merge both branches into one guarded file-serving function.\n\n## References\n- Hardening advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-6865-qjcf-286f (commit d68bd5a); issue #12213.\n- CVE chain: CVE-2026-30869 -> CVE-2026-41894 (GHSA-hjh7-r5w8-5872).\n- serve.go guards commit: https://github.com/siyuan-note/siyuan/commit/bb481e1290c4a34255652ede85a546504505d2a7\n- Residual source (master): `kernel/server/serve.go` `serveExport()` lines 308-312.\n\n## Affected packages\n\n- `github.com/siyuan-note/siyuan/kernel < 0.0.0-20260510110132-b763d787d1f2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/siyuan-note/siyuan/kernel 0.0.0-20260510110132-b763d787d1f2`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}