SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), which only blocks conf/conf.json by exact match and does not restrict the TLS private key (conf/key.pem) or CA private key (conf/ca.key) stored in the same conf/ directory. Because the getFile handler skips the blocklist for RoleAdministrator and all authenticated users receive RoleAdministrator in v3.8.1, any user (or any client on a default no-auth-code instance) can retrieve these private keys via POST /api/file/getFile. On deployments with TLS enabled, this allows decryption of captured HTTPS traffic (key.pem) and forging of certificates trusted by clients that imported SiYuan's CA (ca.key).
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-03 13:06
Updated : 2026-09-08 20:18
NVD link : CVE-2026-85175
Mitre link : CVE-2026-85175
CVE.ORG link : CVE-2026-85175
JSON object : View
Products Affected
No product.
CWE
CWE-552
Files or Directories Accessible to External Parties
