THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-59809 (MEDIUM 4.9) — SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL containing secret placeholders to send plainte

[NVD] CVE-2026-59809 (MEDIUM 4.9) — SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL containing secret placeholders to send plainte

mednvdPublished 2026-08-22

CVE-2026-59809 CVSS: 4.9 MEDIUM Published: 2026-08-22T13:16:39.127

SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL containing secret placeholders to send plaintext secret values to any public host without confirma

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-59809