GHSA-4wwp-f6gw-6qm5

Suggest an improvement
Source
https://github.com/advisories/GHSA-4wwp-f6gw-6qm5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-4wwp-f6gw-6qm5/GHSA-4wwp-f6gw-6qm5.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4wwp-f6gw-6qm5
Aliases
Published
2026-10-05T17:32:48Z
Modified
2026-10-05T17:45:04Z
Summary
SiYuan: TLS Private Keys Readable via getFile (Incomplete Blocklist)
Details

Summary:

IsForbiddenAbsPath() only blocks conf/conf.json by exact match. The TLS private key (conf/key.pem) and CA private key (conf/ca.key) live in the same conf/ directory and are absent from the blocklist. Any authenticated user can retrieve them via POST /api/file/getFile.

Root cause

kernel/util/path_guard.go, IsForbiddenAbsPath() has no entry for TLS key material. The getFile handler at kernel/api/file.go:497 skips the blocklist for RoleAdministrator, and in v3.8.1 all authenticated users receive RoleAdministrator (no non-admin role is currently issued to direct API consumers). The files are generated on every boot regardless of whether TLS is active.

Steps to reproduce:

# No token required on a default no-auth-code instance
curl -s -X POST http://TARGET:6806/api/file/getFile \
  -H "Content-Type: application/json" \
  -d '{"path": "/conf/key.pem"}'
curl -s -X POST http://TARGET:6806/api/file/getFile \
  -H "Content-Type: application/json" \
  -d '{"path": "/conf/ca.key"}'

Response: Raw PEM private key bytes.

2026-08-19_14-19

Impact:

On deployments with TLS enabled (--ssl flag or NetworkServeTLS), possession of key.pem allows decryption of captured HTTPS traffic. Possession of ca.key allows signing certificates trusted by any client that imported SiYuan's locaprompts users to do). The files exist on every installation even whenTLS is currently inactive.

Prior art:

This is the same class of bug as GHSA-9jfx-rc58-h23j (conf.json readable via template render) and GHSA-c8r8-95hg-mp34 (MCP file tool blocklist incomplete). The fix is to add conf/key.pem, conf/ca.key, conf/cert.pem, and conf/ca.crt to IsForbiddenAbsPath().

Database specific
{
    "cwe_ids":  [
        "CWE-552"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-05T17:32:48Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

Go / github.com/siyuan-note/siyuan/kernel

Package

Name
github.com/siyuan-note/siyuan/kernel
View open source insights on deps.dev
Purl
pkg:golang/github.com/siyuan-note/siyuan/kernel

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.0-20260819144130-256d73aa7f94

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-4wwp-f6gw-6qm5/GHSA-4wwp-f6gw-6qm5.json"