THREAT OPS › Threat News › [NVD] CVE-2026-59809 (MEDIUM 4.9) — SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL containing secret placeholders to send plainte
[NVD] CVE-2026-59809 (MEDIUM 4.9) — SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL containing secret placeholders to send plainte
CVE-2026-59809 CVSS: 4.9 MEDIUM Published: 2026-08-22T13:16:39.127
SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL containing secret placeholders to send plaintext secret values to any public host without confirma
Indicators of compromise
- CVE-2026-59809cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-59809