Disclosure summary
### Summary `/api/file/getUniqueFilename` takes a path from the request body and passes it to a filesystem existence check with no validation, confinement or authorization. The response distinguishes paths that exist from paths that do not, so an anonymous reader in publish mode can probe arbitrary locations on the host, one request per probe. Files and directories both work. Every neighbouring file route either requires an administrator or confines the path first. ### Details **Route.** `kernel/api/router.go:289` on master, `:292` on the development branch, `CheckAuth` only. **Handler,** `kernel/api/file.go:84`, in full: ```go util.ParseJsonArgs(arg, ret, util.BindJsonArg("path", &filePath, true, true)) ret.Data = map[string]any{"path": util.GetUniqueFilename(filePath)} ``` **The argument binder does no path handling.** `util.BindJsonArg` (`kernel/util/net.go:365`) takes two booleans, `required` (the key must be present) and `rejectEmpty` (the value must be non-empty). That is its entire contract. There is no `filepath.Clean`, no workspace join, no traversal check. An absolute path outside the workspace reaches `gulu.File.IsExist` unmodified. **The oracle.** `util/file.go:67`: ```
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-hf8h-97gm-4x2p
Open original source · Updated Oct 01, 2026
SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| go | github.com/siyuan-note/siyuan/kernel | < 0.0.0-20260812083335-251596fc0de2 | 0.0.0-20260812083335-251596fc0de2 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-01T11:46:01-04:00
MODIFIED 2026-10-01T11:46:03-04:00
INGESTED 2026-10-06T11:45:02-04:00