Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-27jw-6xjf-hgxj

Опубликовано: 22 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 4.9

Описание

SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL containing secret placeholders to send plaintext secret values to any public host without confirmation.

SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL containing secret placeholders to send plaintext secret values to any public host without confirmation.

EPSS

Процентиль: 15%
0.00244
Низкий

6.9 Medium

CVSS4

4.9 Medium

CVSS3

Дефекты

CWE-201

Связанные уязвимости

CVSS3: 4.9
nvd
5 дней назад

SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL containing secret placeholders to send plaintext secret values to any public host without confirmation.

EPSS

Процентиль: 15%
0.00244
Низкий

6.9 Medium

CVSS4

4.9 Medium

CVSS3

Дефекты

CWE-201