CVE-2026-74798Patch

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. The tool performs only an empty-string check on the id parameter before passing it to RemoveUnusedAttributeView (kernel/model/attribute_view.go), which builds a filesystem path via filepath.Join without validating that id matches SiYuan's node-ID format. An authenticated MCP client can supply path traversal sequences in id to cause the kernel to copy an arbitrary file readable by the process into SiYuan's history directory (arbitrary file read) and then delete the original file (arbitrary file deletion). The corresponding HTTP API handler was hardened in GHSA-7hm9-v7vf-7g4w, but this MCP caller was not.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-08-19)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-18: 1Mentions · 2026-08-19: 2Patch / Workaround · 2026-08-18: 1Patch / Workaround · 2026-08-19: 1Technical Details · 2026-08-18: 1Technical Details · 2026-08-19: 208-1808-19
Signal classification2 categories
Patch
266.7%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-181
Patch1
2026-08-192
General1Patch1
Full discourse3 posts
  • Mohi@disismohi
    Patch

    CVE-2026-74798: SiYuan patched path traversal in their HTTP API. They left the same vulnerability in the MCP tool that calls the same function. Authenticated MCP client → arbitrary file read + delete. CVSS 8.7. Here's what happened.

    Post summary

    SiYuan patched a path traversal flaw (CVE‑2026‑74798) in its HTTP API but left the same issue in the MCP tool, allowing authenticated clients to read and delete arbitrary files; the vulnerability has a CVSS score of 8.7.

    1000061
    75 followersView on X
  • Mohi@disismohi
    General

    Empty-string checks are not input validation. They're a type error that passed code review. Source: https://nvd.nist.gov/vuln/detail/CVE-2026-74798

    Post summary

    The brief commentary cites that empty‑string checks were incorrectly treated as input validation, resulting in a type error, as documented in NVD for CVE‑2026‑74798.

    0000020
    75 followersView on X
  • iSECTECH@isectech_
    Patch

    SiYuan CVE-2026-74798 lets an authenticated MCP client traverse paths, copy readable files into history, then delete originals. Upgrade to 3.7.4 and review which agents can invoke destructive tools. https://github.com/siyuan-note/siyuan/security/advisories/GHSA-43jx-gxq4-jpjc

    Post summary

    The advisory reveals that CVE‑2026‑74798 permits authenticated MCP clients to traverse directories, copy files to history, and delete originals, and advises upgrading to version 3.7.4 to remediate the vulnerability.

    0000035
    86 followersView on X

Explore more