SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-66012

CRITICAL · CVSS 10 EPSS 0.44% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-25 · Last synced 2026-08-24

CyberRota Analysis

AI-Generated

The vulnerability affects SiYuan versions prior to 3.7.2, specifically in the POST /mcp kernel endpoint, which lacks proper authorization checks, allowing unauthenticated remote attackers to exploit 31 MCP tools. The impact includes unauthorized access to sensitive configuration files and the ability to execute arbitrary code, potentially leading to full administrative control of the system. Organizations using SiYuan, especially those with the Publish server in anonymous mode, should prioritize immediate remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-66012
Severity
CRITICAL
CVSS
10
EPSS
0.44%

Original NVD Description

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with list/read/write/delete/rename/copy actions across the entire workspace. When the Publish server is enabled in anonymous mode (Conf.Publish.Enable=true and Conf.Publish.Auth.Enable=false), the Publish reverse proxy attaches an anonymous RoleReader JWT to proxied requests, allowing a remote unauthenticated attacker to reach /mcp. The attacker can read conf/conf.json to extract accessAuthCode, api.token, and cookieKey in plaintext, write arbitrary files in the workspace, and plant a plugin into data/plugins/ that executes with nodeIntegration:true and no contextIsolation on the next desktop launch, leading to administrator takeover.