CVE-2026-82233: SiYuan's asset.upload MCP tool read arbitrary absolute paths; fourth MCP-tool record against the app in August
VulnCheck published CVE-2026-82233 on 2026-08-28: the asset.upload MCP tool in SiYuan before v3.8.1 accepted arbitrary absolute file paths without workspace boundary validation, letting an MCP client read files outside the workspace. The repository advisory went out 2026-08-13 and v3.8.1 shipped the fix on 2026-08-18, ten days before the record. It is the fourth CVE against SiYuan's MCP tool surface published in August 2026.
VulnCheck published CVE-2026-82233 on 2026-08-28 against SiYuan, the
open-source note-taking app whose built-in MCP tool surface has now
drawn four CVE records in a single month. The new record covers the
asset.upload MCP tool, which accepted arbitrary absolute file paths
without validating them against the workspace boundary, so a connected
MCP client could read files anywhere the app could.
The fix predates the record: the repository advisory (GHSA-p23f-cm6q-2qp8, medium) was published 2026-08-13 and v3.8.1 shipped on 2026-08-18, ten days before the CVE record appeared. The record rates it 5.7 medium.
August's ledger against SiYuan's MCP tools now reads: CVE-2026-74798 (database_clean path traversal, recorded 08-18), the CVE-2026-59809 and CVE-2026-60083 pair (http_request secret exfiltration and an incomplete file-tool blocklist, recorded 08-22, fixed v3.8.0), and this asset.upload traversal, fixed one minor version later. Each record so far has trailed its fix; SiYuan sits in the verification queue as a first-party MCP tool surface awaiting a catalog record.
How was this verified, and what are the sources?
Published · confidence 1.00.
- CVE-2026-82233 CNA record (VulnCheck) - "SiYuan before v3.8.1 Path Traversal via asset.upload", 5.7 medium; affected before 3.8.1, unaffected from 3.8.1; published 2026-08-28 - accessed
- Repository advisory GHSA-p23f-cm6q-2qp8 on siyuan-note/siyuan, published 2026-08-13, severity medium - "SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)" - accessed
- SiYuan v3.8.1 release, published 2026-08-18 - the fixed version the CVE record names - accessed