Vulnary
← back to the feed
Critical· 10official fix available

CVE-2026-66012

SiYuan versions earlier than 3.7.2 allow unauthenticated users to access a privileged API that can read, write, and delete files across the workspace. When the Publish server runs in anonymous mode, an attacker can read sensitive configuration, drop malicious plugins, and effectively take over the desktop application. The flaw is a missing authorization check on the /mcp endpoint.

publishedJul 25, 2026
last modifiedJul 28, 2026
sourcesNVD
severity · cvss
10
critical · how bad it is
exploitation · epss
<1%
36th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 24, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

SiYuan desktop application, versions prior to 3.7.2, especially those with the Publish server enabled in anonymous mode (Conf.Publish.Enable=true and Conf.Publish.Auth.Enable=false).

02

Real-world impact

An attacker could read configuration files, write arbitrary files, and install a plugin that runs with full node integration, giving them administrator control over the application.

03

Why this severity

The CVSS score of 10 reflects that the vulnerability is exploitable remotely without authentication, provides complete control over the system, and has no mitigations in place. The high impact on confidentiality, integrity, and availability, combined with the lack of required privileges, results in a critical rating.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade SiYuan to version 3.7.2 or later.
  2. 02Restart the application.

NVD description

05

Timeline

  1. Jul 25, 2026 · 7d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 25, 2026 · 7d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
  3. Jul 28, 2026 · 4d ago
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Attack requirementsNone
Privileges requiredNone
User interactionNone needed
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →