CVE-2026-25992: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-25992 is a file read interface case bypass vulnerability (path traversal) in SiYuan, a personal knowledge management system developed by b3log. The /api/file/getFile endpoint uses case-sensitive string equality checks to block access to sensitive files; on case-insensitive file systems such as Windows, attackers can bypass these restrictions using mixed-case paths to read protected configuration files. All versions prior to 3.5.5 are affected. The vulnerability was published on February 10, 2026, and fixed in v3.5.5 released the same day. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). The /api/file/getFile endpoint performs case-sensitive string matching to block access to sensitive paths, but does not normalize path casing before comparison. On Windows (and other case-insensitive file systems), submitting a path such as cOnf/conf.json instead of conf/conf.json bypasses the blocklist entirely, allowing the file system to resolve the path successfully while the security check fails to match it. Exploitation requires no authentication when the SiYuan service is published without access controls, or when an attacker can inject a valid token into a published service. A proof-of-concept is publicly documented in the GitHub Security Advisory (GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to read sensitive configuration files from the SiYuan data directory, including conf/conf.json, which may contain access codes, API tokens, and synchronization credentials. There is no integrity or availability impact — the vulnerability is limited to unauthorized disclosure of confidential data. Exposure of API tokens or sync credentials could enable further account compromise or lateral movement into connected services (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub Security Advisory, demonstrating exploitation via a simple HTTP POST request with a mixed-case path. The vulnerability is exploitable by unauthenticated attackers over the network with no user interaction required, making it trivially weaponizable against exposed instances. There is no current evidence of in-the-wild exploitation. The EPSS score is approximately 0.043% (low probability of exploitation in the near term), and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (GitHub Advisory, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify internet-facing SiYuan instances (versions ≤ 3.5.4) running on Windows or other case-insensitive file systems, using tools like Shodan or Censys searching for the SiYuan API endpoint.
  2. Verify access: Confirm the /api/file/getFile endpoint is accessible — either because the service is published without authentication, or by obtaining/injecting a valid token.
  3. Craft mixed-case path payload: Construct a JSON POST body with a mixed-case version of a sensitive file path, e.g., {"path":"cOnf/conf.json"} to bypass the case-sensitive blocklist.
  4. Send the request: Issue an HTTP POST to /api/file/getFile with the crafted payload:
    POST /api/file/getFile HTTP/1.1
    Content-Type: application/json
    
    {"path":"cOnf/conf.json"}
  5. Retrieve sensitive data: The server resolves the path on the case-insensitive file system and returns the contents of conf/conf.json, exposing access codes, API tokens, and sync configuration (GitHub Advisory).

Indicators of compromise

  • Network: Unusual HTTP POST requests to /api/file/getFile with JSON bodies containing mixed-case file paths (e.g., cOnf/conf.json, CONF/conf.json); requests originating from unexpected external IP addresses.
  • Logs: SiYuan access logs showing POST requests to /api/file/getFile with non-standard casing in the path parameter, particularly targeting conf/, data/, or other sensitive directories.
  • File System: No direct file system artifacts are created by read-only exploitation; however, monitor for unexpected access patterns to conf/conf.json or similar configuration files in the SiYuan data directory.

Mitigation and workarounds

Upgrade SiYuan to version 3.5.5 or later, which normalizes path casing before comparison and applies blacklist validation on sensitive paths after normalization (commit 399a38893e8719968ea2511e177bb53e09973fa6). If immediate patching is not possible, restrict network access to the /api/file/getFile endpoint using a firewall or reverse proxy, and avoid publishing the SiYuan service without authentication. For Windows deployments, implement OS-level access controls to limit read access to configuration files (GitHub Advisory, SiYuan v3.5.5 Release).

Community reactions

The vulnerability was reported by security researcher EaEa0001 and disclosed via GitHub's coordinated disclosure process. A brief technical write-up was published by infinitsec.net shortly after disclosure. Social media coverage was limited, with a Mastodon post from @thehackerwire noting the advisory. No major vendor statements or significant community debate have been observed beyond the standard advisory publication (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management