CVE-2026-59809

Summary

SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL containing secret placeholders to send plaintext secret values to any public host without confirmation.

Affected Software

VendorProductVersion RangeStatus
siyuan-notesiyuan0 < 3.8.0affected
siyuan-notesiyuan3.8.0unaffected

Weaknesses

  • CWE-201: Insertion of Sensitive Information Into Sent Data

References