Unauthorized File Management in SiYuan by SiYuan Note
CVE-2026-66012

10CRITICAL

Key Information:

Status
Vendor
CVE Published:
25 July 2026

What is CVE-2026-66012?

SiYuan before version 3.7.2 exhibits a significant vulnerability due to missing authorization checks in the POST /mcp kernel endpoint. This flaw permits unauthenticated users to perform actions through 31 MCP tools, including critical file operations such as reading, writing, and deleting files within the entire workspace. When the Publish server is configured to operate in anonymous mode, an attacker can exploit this vulnerability to gain access to sensitive configuration files and potentially insert malicious plugins, leading to unauthorized administrative control over the system.

Affected Version(s)

siyuan 0 < 3.7.2

siyuan 3.7.2

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hypnguyen1209
.