SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-59809

MEDIUM · CVSS 4.9 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

SiYuan versions prior to 3.8.0 are vulnerable due to improper handling of secret placeholders in the destination URL parameter of the http_request MCP tool, enabling attackers to exfiltrate sensitive stored secrets. This vulnerability allows an attacker to craft requests that can send plaintext secret values to any public host without user confirmation. Organizations using affected versions should prioritize remediation to prevent potential data leaks and unauthorized access to sensitive information.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-59809
Severity
MEDIUM
CVSS
4.9
EPSS
0.24%

Original NVD Description

SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL containing secret placeholders to send plaintext secret values to any public host without confirmation.