Skip to main content

Kernel: SiYuan: /history/*path and /repo/diff/*path potentially exposing historical snapshots of data/.siyuan/publishAccess.json and data/templates/*

0
Medium
Published: 10/05/2026 (10/05/2026, 17:32:44 UTC)
Source: GCVE Database
Product: github.com/siyuan-note/siyuan/kernel

Description

### Summary `GHSA-c8r8-95hg-mp34` added a centralized guard, `util.IsForbiddenAbsPath()`, specifically to block access to a small set of sensitive files: `conf/conf.json` (plaintext `accessAuthCode`/API token/cookie key), `data/snippets/conf.json`, the entire `data/templates/` directory, and `data/.siyuan/publishAccess.json` (plaintext publish-mode passwords). It was applied to `kernel/api/file.go` and `kernel/mcp/tools/file.go`. Two other routes in the same server that serve arbitrary files by path, `/history/*path` and `/repo/diff/*path`, construct their target paths independently and were not updated to call this new guard. Since the repo/history snapshot system's tracked root is `data/` (confirmed by `getSyncIgnoreLines()`, whose ignore file lives at `data/.siyuan/syncignore` with entries relative to `data/`), both `data/.siyuan/publishAccess.json` and `data/templates/*` fall within the scope that can legitimately be captured in historical snapshots, meaning a prior version of either file can exist in `util.HistoryDir`/the repo-diff temp checkout even after the live file has been protected by the new guard. This is CWE-862 (Missing Authorization) applied to a very recently introduced protection mechanism. ### Details `kernel/server/serve.go`, `/history/*path` (around line 994): ```go ginServer.GET("/history/*path", model.CheckAuth, model.CheckAdminRole, func(context *gin.Context) { p := filepath.Join(util.HistoryDir, context.Param("path")) // 加密笔记本的历史是密文(.sy/assets/AV),需先解密再输出 if serveEncryptedHistory(context, p) { return } secureAssetContentHeaders(context, p, p) http.ServeFile(context.Writer, context.Request, p) }) ``` No call to `util.IsForbiddenAbsPath(p)` anywhere in this handler. `kernel/server/serve.go`, `/repo/diff/*path` (around line 1241): ```go ginServer.GET("/repo/diff/*path", model.CheckAuth, model.CheckAdminRole, func(context *gin.Context) { requestPath := filepath.Clean(context.Param("path")) if strings.Contains(requestPath, "..") { context.Status(http.StatusUnauthorized) return } ... p := filepath.Join(repoDiffBaseDir, requestPath) if !gulu.File.IsSubPath(repoDiffBaseDir, p) { context.Status(http.StatusUnauthorized) return } http.ServeFile(context.Writer, context.Request, p) }) ``` This route does have its own traversal protection (`..` rejection and `IsSubPath` containment within `repoDiffBaseDir`), but that only prevents escaping the diff-checkout directory, it does nothing to prevent retrieving a *legitimately checked-out historical copy* of `publishAccess.json` or a templates file from within that directory, which is exactly what the new guard exists to prevent regardless of which directory the copy currently sits in. `util.IsForbiddenAbsPath()` itself (`kernel/util/path_guard.go`, introduced by the referenced fix) confirms the intended scope: ```go // 禁止访问 data/.siyuan/publishAccess.json(含发布模式明文访问密码) publishAccessPath := NormalizeAndResolve(filepath.Join(DataDir, ".siyuan", "publishAccess.json")) if fileNorm == publishAccessPath { return true } ``` and ```go // 禁止访问 data/templates 目录(含目录本身及其全部子路径) templatesBase := NormalizeAndResolve(filepath.Join(DataDir, "templates")) if fileNorm == templatesBase || gulu.File.IsSubPath(templatesBase, fileNorm) { return true } ``` Both are paths within `data/`, the same root the sync/history/repo system tracks. ### Step-by-step reproduction 1. As the workspace admin, enable Publish with a password on at least one notebook (creating `data/.siyuan/publishAccess.json` with a plaintext password), then let a sync/backup snapshot capture this state (or check whether local history capture already covers `data/.siyuan/` in the deployed version). 2. Change or remove the publish password, so the live `publishAccess.json` no longer contains the old plaintext password the new guard is meant to hide, going forward. 3. As the admin, request the historical/diff version instead of the live file: ```bash curl -s http://<target>:6806/history/<snapshot-path-to-publishAccess.json> \ -u "<workspaceName>:<accessAuthCode>" curl -s http://<target>:6806/repo/diff/<diff-path-to-publishAccess.json> \ -u "<workspaceName>:<accessAuthCode>" ``` 4. Expected if consistently protected, matching the behavior the new guard already provides on the live-file endpoints: rejected. Observed: neither handler calls `IsForbiddenAbsPath`, so the historical copy is served if it exists in that location. *(Not run against a live compiled kernel, same sandbox limitation noted throughout this review; both handlers are read directly from source at the reviewed commit, and `IsForbiddenAbsPath`'s scope, plus the sync-root confirmation via `getSyncIgnoreLines()`, are quoted directly above. Whether these specific files are captured by history/repo snapshots in a given deployment depends on the workspace's actual usage history and was not indep

CVSS v3.1

Score 4.9medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Affected software

Goghsa
github.com/siyuan-note/siyuan/kernel
Affected versions
<0.0.0-20260816034002-035bf9a8c311

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-3cm4-ccvw-6xr6
Osv Schema Version
1.4.0
Ecosystems
["Go"]
Database Specific Severity
MODERATE
Cvss Version
3.1

Threat ID: 6ac415b52cdf04f6563b4ee5

Added to database: 10/05/2026, 21:25:09 UTC

Last updated: 10/05/2026, 21:25:09 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses