THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-60083 (MEDIUM 4.9) — SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to sensitive workspace files protected by the HTTP API. Authenticated administrators can read plaintext publish-mode passwords from data/.siyuan/publishAccess.jso

[NVD] CVE-2026-60083 (MEDIUM 4.9) — SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to sensitive workspace files protected by the HTTP API. Authenticated administrators can read plaintext publish-mode passwords from data/.siyuan/publishAccess.jso

mednvdPublished 2026-08-22

CVE-2026-60083 CVSS: 4.9 MEDIUM Published: 2026-08-22T13:16:39.263

SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to sensitive workspace files protected by the HTTP API. Authenticated administrators can read plaintext publish-mode passwords from data/.siyuan/publishAccess.json and access other sensitive files like data/templat

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-60083