Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 31 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siyuan
Siyuan siyuan |
|
| Vendors & Products |
Siyuan
Siyuan siyuan |
Mon, 31 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SiYuan before v3.8.1 contains a path traversal vulnerability in the asset.upload MCP tool that accepts arbitrary absolute file paths without workspace boundary validation. Attackers can induce the AI Agent to upload sensitive files such as SSH keys or credentials from outside the workspace into the asset directory through prompt injection. | |
| Title | SiYuan before v3.8.1 Path Traversal via asset.upload | |
| First Time appeared |
B3log
B3log siyuan |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:* | |
| Vendors & Products |
B3log
B3log siyuan |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-31T18:28:15.029Z
Reserved: 2026-08-28T10:37:04.620Z
Link: CVE-2026-82233
Updated: 2026-08-31T18:27:28.427Z
Status : Deferred
Published: 2026-08-28T12:16:32.953
Modified: 2026-08-31T19:17:15.907
Link: CVE-2026-82233
No data.
OpenCVE Enrichment
Updated: 2026-08-31T21:24:50Z