What happened
Agent-accessible recursive tools traverse from an allowed root into protected descendants, returning sensitive lines, copying protected files into readable paths, or overwriting protected files from an archive.
2026-09-26
HighVendor postAnalysis of CVE-2026-100633, where SiYuan MCP recursive file tools could bypass protected-path checks and misleading confirmations hid descendant access.
What happened
Agent-accessible recursive tools traverse from an allowed root into protected descendants, returning sensitive lines, copying protected files into readable paths, or overwriting protected files from an archive.
Why it matters
Potential disclosure of configuration, TLS keys, access settings, notebook internals, and logs, plus unauthorized overwrite of protected workspace files.
Missing authorization check
A decision over the canonical descendant path, exact operation, caller, and payload before each protected read, copy, or overwrite.
Would PP block it?
The gate can reject or hold a recursive operation when any resolved descendant enters a protected path. A receipt must bind the exact file and operation, so a confirmation card showing only an allowed parent cannot authorize hidden child access.
Incident analysis
2026-09-26
CVE-2026-100633 and GHSA-9g6v-r3xf-673q are published for SiYuan 3.8.0 through 3.8.3.
2026-09-26
SiYuan 3.8.4 is identified as the fixed version.
Authorization boundary
This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
A Tool-Call Gate can resolve and evaluate every descendant target before execution instead of inheriting authority from the visible root argument.
Start small
This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.