Résumé
SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)
Détails de l’avis
Summary
SiYuan's /export/ file handler was hardened against export disclosure (issue #12213) by adding an
IsSubPath(exportBaseDir, fullPath) check and an IsSensitivePath() check in commit bb481e1. These guards
were added only to the main branch of the handler. The handler begins with a short-circuit branch:
if strings.HasPrefix(c.Request.URL.Path, "/export/temp/") {
c.File(filepath.Join(util.TempDir, c.Request.URL.Path))
return
}
This branch joins the broader util.TempDir with the raw, percent-decoded request path and serves it with
neither IsSubPath nor IsSensitivePath. An authenticated request to
/export/temp/%2e%2e/.../etc/passwd traverses out of TempDir and reads arbitrary files - exactly the
sensitive-file disclosure the patch intended to prevent. Present in the latest master.
Affected
- From commit
bb481e1(the hardening) through the latest master. - Requires SiYuan access authorization (
model.CheckAuth) - but the patch's stated goal is to deny sensitive-file export even to authorized callers.
Root cause
kernel/server/serve.go serveExport(): the main branch has IsSubPath + IsSensitivePath; the
/export/temp/ short-circuit branch (above it) has neither and uses util.TempDir as its root.
c.Request.URL.Path is percent-decoded by net/http, so %2e%2e becomes .. and filepath.Join collapses it.
Incomplete-fix lineage
- Export disclosure (issue #12213; CVE-2026-30869) -> fix
bb481e1/d68bd5a(GHSA-6865-qjcf-286f): guards on the main branch +IsSensitivePathextended to*.db/*.log. - Follow-up CVE-2026-41894 (GHSA-hjh7-r5w8-5872) in the same
/exportpath family. - The
/export/temp/short-circuit branch was never covered by the guards (this report).
Proof of concept (benign)
- Authenticate (access auth code).
GET /export/<sensitive>(main branch) -> 401/403 (guards work).GET /export/temp/%2e%2e/%2e%2e/.../tmp/<planted-marker>(or/etc/hostname) -> 200 + file content, demonstrating the unguarded traversal. The PoC reads only a planted marker //etc/hostname; no credentials.
Impact
Authenticated arbitrary file read bypassing the sensitive-file protection: /etc/passwd, ~/.ssh/*, SiYuan
*.db workspace data, *.log.
Remediation
- Apply
IsSubPath+IsSensitivePathto the/export/temp/branch (or restrict its root toTempDir/tempwith anIsSubPathcheck). filepath.Cleanthe request path and reject...- Merge both branches into one guarded file-serving function.
References
- Hardening advisory: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-6865-qjcf-286f (commit d68bd5a); issue #12213.
- CVE chain: CVE-2026-30869 -> CVE-2026-41894 (GHSA-hjh7-r5w8-5872).
- serve.go guards commit: https://github.com/siyuan-note/siyuan/commit/bb481e1290c4a34255652ede85a546504505d2a7
- Residual source (master):
kernel/server/serve.goserveExport()lines 308-312.
Références
Vulnérabilités liées
Tout Supply chain →- HIGHCVE-2026-75859
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
- HIGHCVE-2026-75914
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
- HIGHCVE-2026-69086
SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure
- MEDIUMCVE-2026-61625
VictoriaMetrics vmrestore: Path traversal via crafted backup part names escapes restore root
- MEDIUMCVE-2026-75602
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool
- HIGHCVE-2026-63490
Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass