Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

SiYuan path traversal and path guard bypass vulnerabilities

Two path-based vulnerabilities in SiYuan before v3.8.2: a path traversal in asset.upload MCP tool allowing upload of sensitive files via prompt injection, and a case-sensitive path guard bypass enabling reading of protected configuration files.

Disclosed 28 August 2026 · Record updated 13 September 2026

Impact

Attackers can induce AI agents to upload sensitive files like SSH keys and credentials outside workspace boundaries, and read protected configuration files through case-variant path requests.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-82233
  2. github.comhttps://github.com/advisories/GHSA-gwmf-gvp9-fcc2