NPM · JULY 2026 · EARLY WARNING

SiYuan Missing Authorization Vulnerability Under Investigation

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
CVE-2026-66012Severity: CRITICAL

SiYuan versions prior to v3.7.2 appear to contain a critical missing authorization vulnerability in the POST /mcp kernel endpoint, potentially allowing remote unauthenticated attackers to read sensitive configuration files, write arbitrary files, and plant malicious plugins leading to administrator takeover.

What happened

SiYuan before v3.7.2 is under investigation for a missing authorization vulnerability in the POST /mcp kernel endpoint. This vulnerability, if exploited, could allow a remote unauthenticated attacker to read sensitive configuration files, write arbitrary files, and plant a malicious plugin leading to administrator takeover. The vulnerability is reportedly gated only by a general auth check with no admin-role or read-only enforcement, exposing 31 MCP tools including a file tool with extensive actions across the entire workspace. When the Publish server is enabled in anonymous mode, the Publish reverse proxy attaches an anonymous RoleReader JWT to proxied requests, potentially allowing unauthenticated access to /mcp.

To assess your exposure, check if you are using SiYuan versions prior to v3.7.2. If so, it is recommended to upgrade to SiYuan v3.7.2 or later to mitigate the vulnerability. Additionally, review your configuration settings, particularly those related to the Publish server and anonymous access, to ensure they are securely configured. For more detailed information, consult the primary sources linked above.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If siyuan is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats