
CVE-2026-74798: SiYuan patched path traversal in their HTTP API. They left the same vulnerability in the MCP tool that calls the same function. Authenticated MCP client → arbitrary file read + delete. CVSS 8.7. Here's what happened.
Post summary
SiYuan patched a path traversal flaw (CVE‑2026‑74798) in its HTTP API but left the same issue in the MCP tool, allowing authenticated clients to read and delete arbitrary files; the vulnerability has a CVSS score of 8.7.

