Vibe Coding
SiYuan's MCP Tools Let Prompt Injection Upload SSH Keys and Rebind DNS Past the SSRF Guard (CVE-2026-82233, CVE-2026-82234)
Both published 2026-08-28 at 12:16 UTC and fixed in SiYuan v3.8.1: the `asset.upload` MCP tool accepted arbitrary absolute file paths with no workspace boundary validation, so prompt injection could induce the agent to copy SSH keys or credentials from outside the workspace into the asset directory (6.9). The companion bug, CVE-2026-82234 (8.4), is in the `http_request` and `web_fetch` agent tools, which resolved DNS only at guard time and never validated the connect-time resolution, leaving classic DNS rebinding open to cloud instance metadata. This is the third MCP CVE round for SiYuan after CVE-2026-66012 exposed 31 unauthenticated MCP tools before v3.7.2.
Source
↳ Follow the thread