
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23851 is an arbitrary file read vulnerability in SiYuan, a personal knowledge management system developed by b3log. The flaw exists in the /api/file/globalCopyFiles endpoint, which allows authenticated users to copy files from any location on the server's filesystem into the application workspace without proper path validation. All versions prior to 3.5.4 are affected (specifically confirmed in v3.5.3). The vulnerability was disclosed on January 18, 2026, and patched in version 3.5.4. It carries a CVSS v3.1 base score of 6.5 (Medium) and a CVSS v4.0 base score of 8.3 (High) (Github Advisory, Feedly).
The root cause is a path traversal flaw (CWE-22) in kernel/api/file.go. The globalCopyFiles function accepts a JSON array of source file paths (srcs) from the request body and only verifies that each source file exists via filelock.IsExist(src), without checking whether the path is confined to the authorized workspace directory. This allows an attacker to supply arbitrary absolute paths (e.g., /etc/passwd) as source values, causing the application to copy those files into the workspace. The copied files can then be retrieved via the standard file retrieval API, which treats them as legitimate workspace assets. The fix in version 3.5.4 adds absolute path resolution (filepath.Abs), a util.IsSensitivePath() check covering common sensitive files and directories, and applies the same guard to the netAssets2LocalAssets0 function in kernel/model/assets.go (Github Advisory, Patch Commit).
Successful exploitation allows an authenticated attacker to read arbitrary files from the server's filesystem, bypassing intended workspace directory restrictions. Sensitive targets include system files (/etc/passwd, /etc/shadow), SSH private keys, cloud credential files (.aws/credentials, .kube/config), application secrets (.env, docker-compose.yml), and TLS certificates. Exfiltration of these files can enable credential harvesting and lateral movement from the SiYuan application to the broader infrastructure, resulting in a complete loss of confidentiality for both user data and the underlying server environment (Github Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the time of disclosure. The vulnerability requires valid authentication credentials, which limits opportunistic exploitation but does not prevent insider threats or attackers who have obtained credentials through other means. The EPSS score is approximately 0.043–0.053%, placing it in the 17th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory, Feedly).
/etc/passwd, /etc/shadow, ~/.ssh/id_rsa, ~/.aws/credentials, or application-specific secrets like docker-compose.yml./api/file/globalCopyFiles with a JSON body specifying the target system file as the source path and the workspace root as the destination:{
"srcs": ["/etc/passwd"],
"destDir": "/"
}/api/file/globalCopyFiles with srcs values containing absolute paths outside the workspace directory (e.g., /etc/passwd, /root/, /.ssh/, /.aws/).passwd, shadow, id_rsa, credentials).globalCopyFiles calls with source paths referencing system directories (/etc/, /root/, /var/, C:\Users\).passwd, .env, id_rsa, credentials) in the SiYuan workspace directory.refuse to copy sensitive file [<path>] may indicate attempted exploitation against an updated instance (Github Advisory, Patch Commit).Upgrade SiYuan to version 3.5.4 or later, which introduces absolute path resolution and a IsSensitivePath() validation function blocking access to sensitive system files and directories. For organizations unable to patch immediately, implement network-level access controls (e.g., firewall rules or reverse proxy ACLs) to restrict access to the /api/file/globalCopyFiles endpoint to trusted IP addresses only. Additionally, enforce strong authentication controls and monitor API access logs for requests to this endpoint with suspicious source paths (Github Advisory, Patch Commit).
The vulnerability was reported by security researcher jaroslaw-wawiorko and disclosed via GitHub's security advisory process. The SiYuan maintainer (88250) acknowledged and patched the issue promptly in the 3.5.4 milestone. No significant broader media coverage or notable community debate has been identified beyond the GitHub advisory and standard vulnerability database entries (Github Advisory, GitHub Issue).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."