Critical Authorization Vulnerability in SiYuan (CVE-2026-66012)
ID: b059e28e-4980-509a-8568-9e0947a67254
STIX ID: report--b059e28e-4980-509a-8568-9e0947a67254
Feed Name: ThreatCluster
SiYuan versions prior to 3.7.2 are affected by CVE-2026-66012, a critical (CVSS 10) missing-authorization flaw that allows unauthenticated POST /mcp kernel access, exposing 31 MCP tools (including file management), enabling sensitive configuration disclosure, planting of malicious plugins, and arbitrary code execution with administrative privileges; users should upgrade to v3.7.2+ and inspect workspaces for unauthorized files, although no active exploitation or public PoC has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
