Sceawere

Vulnerability Detail

CVE-2026-59809UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SiYuan Secret Exfiltration Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.9
Creation Date
4h ago
Vendor
siyuan-note
Product
siyuan
Attack Type
Insertion of Sensitive Information Into Sent Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL containing secret placeholders to send plaintext secret values to any public host without confirmation.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.9",
  "pubDate": "2026-08-22T13:16:39.127Z",
  "pubdate": "2026-08-22T13:16:39.127Z",
  "executiveSummary": "SiYuan before v3.8.0 suffers from an improper neutralization of secret placeholders leading to unauthorized secret exfiltration. This vulnerability allows an attacker to compromise sensitive data stored within the application.\nThe flaw specifically affects the http_request Model Context Protocol (MCP) tool utilized within the SiYuan ecosystem. Threat actors can leverage this issue to leak stored plaintext secret values to arbitrary public hosts without requiring user confirmation.\nThe risk implication is severe, as sensitive credentials or tokens managed by the application can be harvested remotely. Attackers require the ability to interact with or manipulate an MCP client request to trigger the vulnerable parameter interpolation.\nExploitation relies on crafting malicious payloads that exploit the insecure handling of secret placeholders within the destination URL parameter. Affected systems include all SiYuan deployments running versions prior to v3.8.0.",
  "technicalDetails": "The vulnerability resides within the http_request MCP tool implemented in SiYuan prior to v3.8.0. The root cause is the insecure interpolation of secret placeholders directly into the destination URL parameter during execution.\nWhen an MCP client processes a crafted request containing an attacker-controlled URL with embedded secret placeholders, the application resolves these placeholders into their plaintext secret values. Subsequently, the component issues an outbound HTTP request containing these sensitive values to the specified destination.\nThe attack flow proceeds as follows: First, an attacker constructs a malicious payload targeting the http_request tool, specifying an external public host under their control as the destination URL. This URL incorporates internal secret placeholders recognized by the SiYuan environment. Second, the MCP client submits this request to the vulnerable application logic. Third, the http_request tool automatically interpolates the stored secrets into the URL string, replacing the placeholders with actual plaintext values. Finally, the application executes the HTTP request, transmitting the plaintext secrets to the attacker-controlled server over the network.\nThis behavior bypasses user confirmation mechanisms, allowing silent and automated exfiltration of sensitive data. The vulnerability requires an adversary to successfully interact with or command an MCP client to issue the malicious request, exposing internal configuration or authentication secrets stored within the SiYuan environment to external entities."
}
CVE-2026-59809: SiYuan Secret Exfiltration Vulnerability (MEDIUM Severity, CVSS: 4.9) - Sceawere