在 SiYuan v3.8.0 版本之前,存在一个漏洞,该漏洞允许攻击者从目标应用程序中窃取存储的机密数据。具体来说,http_request MCP 工具会将机密占位符直接插入到目标 URL 参数中,从而导致机密信息泄露。攻击者可以构造一个包含由他们控制的 URL 的 MCP 客户端请求,该 URL 中包含机密占位符,从而将明文状态的机密值发送到任何公共主机,且此过程无需确认。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| siyuan-note | siyuan | < 3.8.0 |
affected |
3.8.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.8.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-60084 | 8.7 HIGH | SiYuan before v3.7.4 Arbitrary File Deletion via removeTemplate |
| CVE-2026-62204 | 6.6 MEDIUM | SiYuan before v3.7.4 Plugin Overwrite via Bazaar Install |
| CVE-2026-60083 | 4.9 MEDIUM | SiYuan before v3.8.0 Incomplete Path Blocklist via MCP file tool |
No comments yet