CVE-2026-59809
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
22/08/2026
Last modified:
22/08/2026
Description
SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL containing secret placeholders to send plaintext secret values to any public host without confirmation.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
4.90
Severity 3.x
MEDIUM



