What is CVE-2026-66012?
SiYuan note-taking app versions prior to v3.7.2 contain a missing authorization vulnerability in the POST /mcp kernel endpoint, lacking proper role enforcement beyond a general auth check. This exposes 31 MCP tools, including file operations like read, write, and delete, to unauthorized actors. Immediate update to version v3.7.2 or later is recommended.
Azərbaycanca: SiYuan qeyd tətbiqinin v3.7.2-dən əvvəlki versiyalarında POST /mcp kernel endpoint-də kritik icazə boşluğu aşkarlanıb. Yalnız ümumi autentifikasiya tələb edən bu nöqtə, admin rolu olmadan da fayl əməliyyatları (oxuma, yazma, silmə) daxil olmaqla 31 MCP alətinə giriş imkanı verir. Dərhal v3.7.2 və ya sonrakı versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: SiYuan
FAQ2
What vulnerability was discovered in SiYuan versions before v3.7.2 at the POST /mcp endpoint?
A missing authorization vulnerability was discovered in the POST /mcp kernel endpoint. It requires only a general auth check, exposing 31 MCP tools, including file operations, without enforcing the admin role.
What action is recommended to mitigate this vulnerability?
Immediate update to SiYuan version v3.7.2 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.