Fetching from the wire…
Security2026-08-28 · source-backed
The http_request and web_fetch agent tools in SiYuan before v3.8.1 validate only the safety-check resolution, so an attacker answers the guard lookup with a public address and the real lookup with an internal one (NVD). The paired CVE-2026-82233 is a path traversal in the asset.upload MCP tool that accepts absolute paths with no workspace boundary, letting an agent be induced to upload SSH keys from outside the workspace.
Each link below shares sources, entities, or timing with this story.
Claude Code uses MCP / Shared entities / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Claude Code uses MCP); both cover CVE, NVD; reported by the same outlet (nvd.nist.gov).
OpenAI supports MCP / Shared entities / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (OpenAI supports MCP); both cover CVE, MCP; overlapping topics (agent, tool).
MCP uses Docker / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (MCP uses Docker); both cover CVE, MCP; overlapping topics (agent, answer, boundary).
Claude uses MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Claude uses MCP); both cover CVE, MCP; overlapping topics (agent, tool).
Cursor uses MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Cursor uses MCP); both cover CVE, MCP; overlapping topics (path, tool).
Claude uses MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Claude uses MCP); both cover MCP, SSH; overlapping topics (accept, agent).
Windsurf uses MCP / Shared entities / Shared topic / Earlier coverage
Linked by a graph relationship (Windsurf uses MCP); both cover CVE, MCP; overlapping topics (agent, tool).
Microsoft supports MCP / Shared entities / Earlier coverage / Tension
Linked by a graph relationship (Microsoft supports MCP); both cover CVE, MCP; earlier CVE coverage from 2026-03-23.