
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23850 is an arbitrary file read (Local File Disclosure/LFD) vulnerability in SiYuan, a personal knowledge management system developed by b3log. The vulnerability affects all versions prior to 3.5.4 and stems from unrestricted server-side HTML rendering in the Markdown feature, which allows attackers to read arbitrary files from the host system. It was disclosed on January 18, 2026 via a GitHub Security Advisory and published to NVD on January 19, 2026. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 7.8 (High) (GitHub Advisory, Red Hat CVE).
The root cause is improper limitation of pathname access (CWE-22 — Path Traversal). In the vulnerable createDocWithMd API endpoint (kernel/api/filetree.go, lines 799–886), the markdown parameter is passed directly to model.CreateWithMarkdown without sanitization. This value is subsequently passed to luteEngine.Md2BlockDOM(md, false) in kernel/model/file.go (line 1035), also without sanitization. An attacker can embed a Markdown hyperlink using a file:// URI (e.g., [loot](file:///etc/passwd)) which, when the document's network assets are converted to local assets via the /api/format/netAssets2LocalAssets endpoint, causes the server to fetch and store the referenced local file as an asset — making it retrievable via the /assets/ endpoint. The vulnerability also enables SSRF by substituting arbitrary HTTP URLs in place of file:// URIs (GitHub Advisory, Patch Commit).
Successful exploitation allows an unauthenticated network attacker to read arbitrary files from the server's filesystem, including sensitive files such as /etc/passwd, SSH private keys, .env files, AWS credentials, and Kubernetes service account tokens. The vulnerability also enables SSRF, allowing attackers to probe and interact with internal network services not directly accessible from the internet. There is no integrity or availability impact, but the confidentiality impact is rated High, as virtually any file readable by the SiYuan process can be exfiltrated (GitHub Advisory).
A fully functional Python proof-of-concept exploit is publicly available in the GitHub Security Advisory, demonstrating both LFD and SSRF attack chains. The exploit requires no authentication and no user interaction, and operates over the network with low attack complexity. The vulnerability was discovered by the team @0xL4ugh during the Null CTF 2025 competition, where it was used as an unintended solution. The EPSS score is approximately 0.055% (low probability of near-term mass exploitation), and there is no evidence of in-the-wild exploitation or CISA KEV catalog listing as of the time of disclosure (GitHub Advisory, Feedly).
authCode via a POST to /api/system/loginAuth with {"authCode": "<password>", "rememberMe": true}./api/notebook/lsNotebooks to retrieve an existing notebook ID./api/filetree/createDocWithMd with a payload such as {"notebook": "<notebook_id>", "path": "/pwn", "markdown": "[loot](file:///etc/passwd)"} to create a document containing a file:// URI referencing the target file. Record the returned doc_id./api/format/netAssets2LocalAssets with {"id": "<doc_id>"} to cause the server to fetch the referenced local file and store it as an asset./api/file/readDir with {"path": "/data/assets"} to list stored assets and identify the newly created file (named with a network-asset-<filename>- prefix).http://<target>:6806/assets/<asset_filename> to retrieve the contents of the target file (GitHub Advisory)./api/filetree/createDocWithMd containing file:// URIs or unusual external URLs in the markdown parameter; POST requests to /api/format/netAssets2LocalAssets shortly after document creation; GET requests to /assets/network-asset-* for files not created by legitimate users.network-asset-passwd-*, network-asset-shadow-*, network-asset-id_rsa-*, or similar sensitive filenames in the SiYuan /data/assets/ directory./api/system/loginAuth, /api/notebook/lsNotebooks, /api/filetree/createDocWithMd, /api/format/netAssets2LocalAssets, and /api/file/readDir from the same source IP in rapid succession.The vendor has released SiYuan version 3.5.4, which addresses this vulnerability by introducing a IsSensitivePath() function in kernel/util/path.go that blocks access to sensitive files and directories (e.g., /etc/passwd, /etc/shadow, SSH keys, .env files, AWS credentials, Kubernetes tokens) during asset conversion and file copy operations. All users running versions prior to 3.5.4 should upgrade immediately. As a temporary workaround if patching is not immediately possible, restrict network access to the SiYuan instance (port 6806) to trusted hosts only using firewall rules or network segmentation (Patch Commit, GitHub Advisory).
The vulnerability was discovered and reported by the @0xL4ugh CTF team (members: abdoghazy2015, xtromera, A-Z4ki, ZeyadZonkorany, and KarimTantawey) during the Null CTF 2025 competition, where it served as an unintended solution to a challenge. The SiYuan maintainers acknowledged the LFD component as a valid vulnerability and addressed it in version 3.5.4, though they explicitly noted that the SSRF component would not be treated as a vulnerability and would not receive a separate fix (GitHub Issue, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."