Posts tagged

RCE
← Back to all posts
HB

MCP as a Backdoor: CVE-2026-66012 — How a Missing Authorization Check in SiYuan's MCP Endpoint Turns Anonymous Readers into Administrators

On July 25, 2026, NIST’s National Vulnerability Database published CVE-2026-66012, a missing-authorization vulnerability in SiYuan — the privacy-first, block-level note-taking application with over 45,000 GitHub stars and a large Docker-hosted user base. NVD scores it 10.0…