CVE-2026-85175: Siyuan-Note Siyuan
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), which only blocks conf/conf.json by exact match and does not restrict the TLS private key (conf/key.pem) or CA private key (conf/ca.key) stored in the same conf/ directory. Because the getFile handler skips the blocklist for RoleAdministrator and all authenticated users receive RoleAdministrator in v3.8.1, any user (or any client on a default no-auth-code instance) can retrieve these private keys via POST /api/file/getFile. On deployments with TLS enabled, this allows decryption of captured HTTPS traffic (key.pem) and forging of certificates trusted by clients that imported SiYuan's CA (ca.key).
Affected products
- Siyuan-Note Siyuan: before 3.8.2 (fixed in 3.8.2)
Published 2026-09-03. Last modified 2026-09-08.