{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-66012/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":10,"id":"CVE-2026-66012"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SiYuan \u003c v3.7.2"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","rce","authorization-bypass","siyuan","cve-2026-66012"],"_cs_type":"advisory","_cs_vendors":["SiYuan"],"content_html":"\u003cp\u003eA critical missing authorization vulnerability, tracked as CVE-2026-66012, affects SiYuan versions prior to 3.7.2. This flaw exists in the POST /mcp kernel endpoint, which lacks proper administrative role enforcement and is only protected by a general authentication check. When the SiYuan Publish server is configured in anonymous mode (Conf.Publish.Enable=true and Conf.Publish.Auth.Enable=false), a remote unauthenticated attacker can exploit this vulnerability. The Publish reverse proxy, in this configuration, attaches an anonymous RoleReader JWT to proxied requests, granting the attacker access to 31 internal MCP tools. These tools include a file utility with comprehensive read, write, delete, rename, and copy capabilities across the entire workspace. Exploitation enables attackers to read sensitive configuration files containing plaintext API tokens and cookies, write arbitrary files, and plant malicious plugins that execute with elevated privileges upon the next desktop application launch, leading to complete system compromise and administrator takeover.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe SiYuan Publish server is enabled in anonymous mode, specifically with \u003ccode\u003eConf.Publish.Enable=true\u003c/code\u003e and \u003ccode\u003eConf.Publish.Auth.Enable=false\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eA remote unauthenticated attacker initiates a request targeting the \u003ccode\u003e/mcp\u003c/code\u003e kernel endpoint.\u003c/li\u003e\n\u003cli\u003eThe Publish reverse proxy intercepts the request and, due to the anonymous configuration, attaches an anonymous \u003ccode\u003eRoleReader\u003c/code\u003e JWT to it before forwarding to the kernel.\u003c/li\u003e\n\u003cli\u003eThe attacker leverages the compromised access to the \u003ccode\u003e/mcp\u003c/code\u003e endpoint's \u0026quot;file tool\u0026quot; to read \u003ccode\u003econf/conf.json\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eSensitive credentials, including \u003ccode\u003eaccessAuthCode\u003c/code\u003e, \u003ccode\u003eapi.token\u003c/code\u003e, and \u003ccode\u003ecookieKey\u003c/code\u003e, are extracted by the attacker from the plaintext \u003ccode\u003econf.json\u003c/code\u003e file.\u003c/li\u003e\n\u003cli\u003eUsing the file tool's capabilities, the attacker writes arbitrary files into the SiYuan workspace.\u003c/li\u003e\n\u003cli\u003eThe attacker plants a malicious plugin into the \u003ccode\u003edata/plugins/\u003c/code\u003e directory within the SiYuan application data path.\u003c/li\u003e\n\u003cli\u003eUpon the next desktop launch of the SiYuan application, the malicious plugin executes with \u003ccode\u003enodeIntegration:true\u003c/code\u003e and no \u003ccode\u003econtextIsolation\u003c/code\u003e, resulting in administrator takeover of the underlying system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-66012 allows a remote unauthenticated attacker to achieve full administrator takeover of the system running the vulnerable SiYuan desktop application. This includes the ability to read and exfiltrate sensitive configuration data containing API tokens and session cookies, manipulate or destroy any data within the SiYuan workspace, and execute arbitrary code with the privileges of the desktop user. The CVSS v3.1 Base Score of 10.0 reflects the critical nature and severe consequences of this vulnerability, affecting all users of SiYuan desktop clients before version 3.7.2 operating with a misconfigured Publish server.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-66012 immediately by upgrading SiYuan to version 3.7.2 or later to address the missing authorization vulnerability.\u003c/li\u003e\n\u003cli\u003eReview the SiYuan Publish server configuration. Ensure that \u003ccode\u003eConf.Publish.Enable\u003c/code\u003e is not set to \u003ccode\u003etrue\u003c/code\u003e concurrently with \u003ccode\u003eConf.Publish.Auth.Enable\u003c/code\u003e set to \u003ccode\u003efalse\u003c/code\u003e. Enable authentication for the Publish server.\u003c/li\u003e\n\u003cli\u003eImplement file integrity monitoring for the \u003ccode\u003edata/plugins/\u003c/code\u003e directory within your SiYuan application workspace to detect unauthorized modifications or additions.\u003c/li\u003e\n\u003cli\u003eMonitor for unusual process creation events originating from the SiYuan desktop client application, especially any child processes launched with suspicious arguments or exhibiting elevated privileges not typically associated with legitimate SiYuan operations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-25T11:19:14Z","date_published":"2026-07-25T11:19:14Z","id":"https://feed.craftedsignal.io/briefs/2026-07-siyuan-mcp-authz/","summary":"A critical missing authorization vulnerability, CVE-2026-66012, in SiYuan before version 3.7.2 allows a remote unauthenticated attacker to exploit the POST /mcp kernel endpoint when the Publish server is in anonymous mode, leading to arbitrary file writes, sensitive credential exposure, malicious plugin execution, and ultimately administrator takeover on affected systems.","title":"SiYuan Missing Authorization Vulnerability in /mcp Endpoint (CVE-2026-66012)","url":"https://feed.craftedsignal.io/briefs/2026-07-siyuan-mcp-authz/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-66012","version":"https://jsonfeed.org/version/1.1"}