Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59809

Опубликовано: 22 авг. 2026
Источник: nvd
CVSS3: 4.9
EPSS Низкий

Описание

SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL containing secret placeholders to send plaintext secret values to any public host without confirmation.

EPSS

Процентиль: 15%
0.00244
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-201

Связанные уязвимости

CVSS3: 4.9
github
5 дней назад

SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL containing secret placeholders to send plaintext secret values to any public host without confirmation.

EPSS

Процентиль: 15%
0.00244
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-201