SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85580

MEDIUM · CVSS 6.5 EPSS 0.53% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

SiYuan versions prior to 3.8.2 are vulnerable to a path guard bypass in the MCP file-access handler, allowing attackers to exploit case-sensitive file matching on Linux filesystems. This vulnerability enables unauthorized access to the sensitive publishAccess.json file, potentially exposing critical publish-access configurations and metadata. Organizations using affected versions should prioritize patching to mitigate the risk of sensitive data disclosure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85580
Severity
MEDIUM
CVSS
6.5
EPSS
0.53%
Linux

Original NVD Description

SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems. Attackers can read the protected publishAccess.json file by requesting case-variant paths like PublishAccess.json to disclose sensitive publish-access configuration and metadata.