CVE-2026-66012
SiYuan versions earlier than 3.7.2 allow unauthenticated users to access a privileged API that can read, write, and delete files across the workspace. When the Publish server runs in anonymous mode, an attacker can read sensitive configuration, drop malicious plugins, and effectively take over the desktop application. The flaw is a missing authorization check on the /mcp endpoint.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
SiYuan desktop application, versions prior to 3.7.2, especially those with the Publish server enabled in anonymous mode (Conf.Publish.Enable=true and Conf.Publish.Auth.Enable=false).
Real-world impact
An attacker could read configuration files, write arbitrary files, and install a plugin that runs with full node integration, giving them administrator control over the application.
Why this severity
The CVSS score of 10 reflects that the vulnerability is exploitable remotely without authentication, provides complete control over the system, and has no mitigations in place. The high impact on confidentiality, integrity, and availability, combined with the lack of required privileges, results in a critical rating.
What to do about it
- 01Upgrade SiYuan to version 3.7.2 or later.
- 02Restart the application.
NVD description
Timeline
- Jul 25, 2026 · 7d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 25, 2026 · 7d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 28, 2026 · 4d agoAdvisory updatedThe NVD record was last revised.