logo

Critical Authorization Vulnerability in SiYuan (CVE-2026-66012)

ID: b059e28e-4980-509a-8568-9e0947a67254

STIX ID: report--b059e28e-4980-509a-8568-9e0947a67254

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-07-26

Date Updated: 2026-07-26

...
...

SiYuan versions prior to 3.7.2 are affected by CVE-2026-66012, a critical (CVSS 10) missing-authorization flaw that allows unauthenticated POST /mcp kernel access, exposing 31 MCP tools (including file management), enabling sensitive configuration disclosure, planting of malicious plugins, and arbitrary code execution with administrative privileges; users should upgrade to v3.7.2+ and inspect workspaces for unauthorized files, although no active exploitation or public PoC has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.