GHSA-4wwp-f6gw-6qm5Medium▾ SunlitSiYuan: TLS Private Keys Readable via getFile (Incomplete Blocklist)
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
IsForbiddenAbsPath() only blocks conf/conf.json by exact match. The TLS private key (conf/key.pem) and CA private key (conf/ca.key) live in the same conf/ directory and are absent from the blocklist. Any authenticated user can retrieve them via POST /api/file/getFile.
kernel/util/path_guard.go, IsForbiddenAbsPath() has no entry for TLS key material. The getFile handler at kernel/api/file.go:497 skips the blocklist for RoleAdministrator, and in v3.8.1 all authenticated users receive RoleAdministrator (no non-admin role is currently issued to direct API consumers). The files are generated on every boot regardless of whether TLS is active.
# No token required on a default no-auth-code instance
curl -s -X POST http://TARGET:6806/api/file/getFile \
-H "Content-Type: application/json" \
-d '{"path": "/conf/key.pem"}'
curl -s -X POST http://TARGET:6806/api/file/getFile \
-H "Content-Type: application/json" \
-d '{"path": "/conf/ca.key"}'
Response: Raw PEM private key bytes.
<img width="927" height="467" alt="2026-08-19_14-19" src="https://github.com/user-attachments/assets/12e0787f-6bfc-416a-b5ad-a22954e45c48" />On deployments with TLS enabled (--ssl flag or NetworkServeTLS), possession of key.pem allows decryption of captured HTTPS traffic. Possession of ca.key allows signing certificates trusted by any client that imported SiYuan's locaprompts users to do). The files exist on every installation even whenTLS is currently inactive.
This is the same class of bug as GHSA-9jfx-rc58-h23j (conf.json readable via template render) and GHSA-c8r8-95hg-mp34 (MCP file tool blocklist incomplete). The fix is to add conf/key.pem, conf/ca.key, conf/cert.pem, and conf/ca.crt to IsForbiddenAbsPath().
github.com/siyuan-note/siyuan/kernel < 0.0.0-20260819144130-256d73aa7f94Upgrade to a patched release:
github.com/siyuan-note/siyuan/kernel 0.0.0-20260819144130-256d73aa7f94Connected by shared product, vendor, weakness, or advisory.
GHSA-3cm4-ccvw-6xr6Medium· 4.9SiYuan: /history/*path and /repo/diff/*path potentially exposing historical snapshots of data/.siyuan/publishAccess.json and data/templates/*
CVE-2026-82234High· 8.2SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)
CVE-2026-82233Medium· 5.7SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)
GHSA-x8p6-569w-fmmrLow· 8.2Duplicate Advisory: SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` bypass
CVE-2026-74802Low· 0.0SiYuan: Cross-Site WebSocket Hijacking on the admin-only network proxy endpoint (`/ws/network/proxy`) via explicit `CheckOrigin: true` by…
GHSA-69jp-f2p8-9vrgHigh· 7.5Duplicate Advisory: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mode readers