VYPR

siyuan

by GitHub

CVEs (1)

  • CVE-2026-66012CriJul 25, 2026
    risk 0.65cvss 10.0epss 0.01

    SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with…