Skip to content
PERMISSION/PROTOCOL
Back to incident tracker

2026-09-26

HighVendor post

SiYuan MCP Recursive File Tools Could Bypass Sensitive-Path Protections for Reads, Copies, and Overwrites

Analysis of CVE-2026-100633, where SiYuan MCP recursive file tools could bypass protected-path checks and misleading confirmations hid descendant access.

SiYuanTool execution / MCPIncomplete authorization check in recursive MCP file operationsSiYuan 3.8.0 through 3.8.3 in-app Agent and external MCP file server

What happened

Agent-accessible recursive tools traverse from an allowed root into protected descendants, returning sensitive lines, copying protected files into readable paths, or overwriting protected files from an archive.

Why it matters

Potential disclosure of configuration, TLS keys, access settings, notebook internals, and logs, plus unauthorized overwrite of protected workspace files.

Missing authorization check

A decision over the canonical descendant path, exact operation, caller, and payload before each protected read, copy, or overwrite.

Would PP block it?

The gate can reject or hold a recursive operation when any resolved descendant enters a protected path. A receipt must bind the exact file and operation, so a confirmation card showing only an allowed parent cannot authorize hidden child access.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-09-26

    CVE-2026-100633 and GHSA-9g6v-r3xf-673q are published for SiYuan 3.8.0 through 3.8.3.

  2. 2026-09-26

    SiYuan 3.8.4 is identified as the fixed version.

Technical breakdown

  • resolvePath applied the protected-workspace-file denylist to the allowed recursive root but not to each resolved descendant.
  • file.grep could return matching lines from non-hidden protected descendants and was globally classified as safe, so it received no per-call confirmation.
  • file.copy could move protected descendants to ordinary paths where file.read could retrieve them.
  • unzip could overwrite protected descendants with lexically contained archive member names, while confirmation displayed only the allowed root.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
MCP file-tool boundary after canonical path resolution and before each descendant operation
Still needs
Permission Protocol does not patch SiYuan, reduce the administrator credential's other API privileges, or replace filesystem least privilege.
Receipt required for
Reading, copying, extracting into, or overwriting each protected descendant path reached by an agent tool

A Tool-Call Gate can resolve and evaluate every descendant target before execution instead of inheriting authority from the visible root argument.

Start small

Put the relevant gate at this action boundary.

This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop