Remote Secret Exfiltration Vulnerability in SiYuan by SiYuan Team
CVE-2026-59809
6.9MEDIUM
What is CVE-2026-59809?
The vulnerability in SiYuan before version 3.8.0 allows attackers to exfiltrate sensitive stored secrets via manipulated destination URL parameters in the http_request MCP tool. By crafting requests with an attacker-controlled URL that contains secret placeholders, an MCP client can inadvertently transmit plaintext secret values to any public host without any confirmation, posing a significant risk to data confidentiality and integrity.
Affected Version(s)
siyuan 0 < 3.8.0
siyuan 3.8.0
