IsForbiddenAbsPath() only blocks conf/conf.json by exact match. The TLS private key (conf/key.pem) and CA private key (conf/ca.key) live in the same conf/ directory and are absent from the blocklist. Any authenticated user can retrieve them via POST /api/file/getFile.
kernel/util/path_guard.go, IsForbiddenAbsPath() has no entry for TLS key material. The getFile handler at kernel/api/file.go:497 skips the blocklist for RoleAdministrator, and in v3.8.1 all authenticated users receive RoleAdministrator (no non-admin role is currently issued to direct API consumers). The files are generated on every boot regardless of whether TLS is active.
# No token required on a default no-auth-code instance
curl -s -X POST http://TARGET:6806/api/file/getFile \
-H "Content-Type: application/json" \
-d '{"path": "/conf/key.pem"}'
curl -s -X POST http://TARGET:6806/api/file/getFile \
-H "Content-Type: application/json" \
-d '{"path": "/conf/ca.key"}'
Response: Raw PEM private key bytes.
On deployments with TLS enabled (--ssl flag or NetworkServeTLS), possession of key.pem allows decryption of captured HTTPS traffic. Possession of ca.key allows signing certificates trusted by any client that imported SiYuan's locaprompts users to do). The files exist on every installation even whenTLS is currently inactive.
This is the same class of bug as GHSA-9jfx-rc58-h23j (conf.json readable via template render) and GHSA-c8r8-95hg-mp34 (MCP file tool blocklist incomplete). The fix is to add conf/key.pem, conf/ca.key, conf/cert.pem, and conf/ca.crt to IsForbiddenAbsPath().
{
"cwe_ids": [
"CWE-552"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-05T17:32:48Z",
"nvd_published_at": null,
"severity": "MODERATE"
}