CVE-2026-66012 is a critical missing authorization vulnerability in SiYuan before version 3.7.2 affecting the kernel POST /mcp endpoint. The endpoint is protected only by a general authentication check and does not enforce administrator-role restrictions or read-only constraints. In deployments where the Publish server is enabled in anonymous mode, the publish reverse proxy forwards requests with an anonymous reader-role token, which still allows access to the MCP interface. As a result, a remote unauthenticated attacker can reach exposed MCP tools, including a file-management capability that supports listing, reading, writing, deleting, renaming, and copying content across the entire workspace. This permits disclosure of plaintext secrets stored in configuration, arbitrary modification of workspace data, and placement of a malicious plugin that will execute on the next desktop launch under an unsafe Electron configuration, ultimately enabling full administrator takeover.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a small standalone PoC with two files: a README describing CVE-2026-66012 and a single Python exploit script (exploit.py). The exploit targets SiYuan versions before 3.7.2 and abuses missing authorization on the MCP endpoint when the Publish server is enabled in anonymous mode. The script is not part of a larger exploit framework. The exploit flow is straightforward and operational: it performs an MCP JSON-RPC initialize handshake against POST /mcp, captures the returned Mcp-Session-Id header, then invokes the MCP file tool via tools/call to read conf/conf.json. It parses that file with regex to recover sensitive values including accessAuthCode, cookieKey, and api.token. If plugin planting is enabled, it writes two files under data/plugins/pwn: plugin.json and index.js. The JavaScript payload uses Node's child_process.exec() to run an attacker-supplied shell command, defaulting to 'id', when the plugin is loaded on the next desktop launch. Finally, the script derives an admin URL on port 6806 from the supplied Publish URL and posts the stolen accessAuthCode to /api/system/loginAuth to obtain an administrator session token. Primary capabilities: unauthenticated access to the MCP endpoint, arbitrary file read of the SiYuan workspace configuration, arbitrary file write into the plugin directory, delayed remote code execution on next desktop launch, and administrator takeover through reuse of the stolen auth code. The exploit is more than a detector and includes a working payload path, but customization is basic and hardcoded, so OPERATIONAL is the best maturity fit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously remediated SiYuan MCP vulnerability whose fixes required administrator authorization for the MCP endpoint and blocked access to conf/conf.json through the file tool. It is discussed as the predecessor to the current advisory: those controls did not address arbitrary file reads through asset.upload. This reference does not fully describe the original vulnerability or its affected versions.
A critical missing-authorization vulnerability in SiYuan's MCP endpoint (/mcp) that allows unauthorized access to MCP tools when publish/auth configuration permits anonymous access; the vulnerable behavior returns HTTP 200 with tool listings, while the patched behavior returns HTTP 403.
A critical missing authorization vulnerability in SiYuan before 3.7.2 affecting the /mcp kernel endpoint. In anonymous Publish mode, a remote unauthenticated attacker can access exposed MCP tools to read sensitive configuration, modify workspace files, and achieve administrator takeover/RCE via malicious plugin planting.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.