Signal is active with 1 mentions in latest observed window
Immediate actions
Patch affected systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and related endpoints to extract in-memory secrets including AccessAuthCode and AI provider API keys.
SiYuan CVE-2026-74799 can expose unauthenticated pprof data—and in-memory AI API keys—when runtime mode is not exactly prod. Upgrade to 3.7.4, block /debug/pprof/, and rotate keys after exposure. https://github.com/siyuan-note/siyuan/security/advisories/GHSA-9cqq-p2hw-mj3f
Post summary
The advisory reports that SiYuan CVE‑2026‑74799 allows unauthenticated access to pprof data and in‑memory AI API keys in non‑prod modes, and it advises users to upgrade to version 3.7.4, block the /debug/pprof/ endpoint, and rotate exposed keys.
NewNormal Security turns the last 24 hours of CVEs into new detections, every day.
𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 17 Aug 2026
𝗔𝗹𝗿𝗲𝗮𝗱𝘆 𝗰𝗼𝘃𝗲𝗿𝗲𝗱 by NewScan:
🖥️ Go pprof left on a public listener — heap dumps, and the app's own access code, with no login (SiYuan CVE-2026-74799)
𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆:
⚡ MCP code interpreter escaping its sandbox — RCE on the MCP host from one prompt injection (pptr-mcp CVE-2026-19958, Jij-MCP-Server CVE-2026-19964)
📦 WordPress plugin leaking its stored integration credentials to any URL an anonymous visitor names (WooMS CVE-2026-13700)
𝗔𝗱𝗱𝗲𝗱 𝘁𝗼 𝗡𝗲𝘄𝗦𝗰𝗮𝗻 𝗣𝗿𝗼 — 𝗼𝘂𝘁-𝗼𝗳-𝗯𝗮𝗻𝗱:
🔀 MCP tool fetching a caller-supplied URL — internal services and cloud metadata via the agent's own tool call (facebook-ads-mcp-server CVE-2026-19956, graphlit-mcp-server CVE-2026-19957, mcp-florence2 CVE-2026-19984, PromptShopMCP CVE-2026-74842)
Test your stack with NewScan — free, self-hosted:
https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve
#infosec#AppSec#MCP#CSO#REDTEAM
Post summary
NewNormal Security’s daily CVE alert lists several newly covered CVEs with brief impact notes, but contains no PoC, exploit code, patch, or evidence of active exploitation.