CVE-2026-59809
SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to
CVSS
4.9
Medio
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 22 ago 2026 · Última mod.: 22 ago 2026 · CWE-201
Sin historial EPSS suficiente todavía.
SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL containing secret placeholders to send plaintext secret values to any public host without confirmation.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-63481—39.2%
——12Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In version 8.0.1 and earlier, the redirect handling in packages/hurl/src/http/client.rs strips Authorization and Cookie headers and basic-auth credentials when a redirect changes host, but it carries RequestSpec.cookies created from the dedicated [Cookies] section into the redirected request. An attacker-controlled redirect can therefore receive authentication or session cookies that should remain scoped to the original host. Cookies supplied through a raw Cookie header are stripped and are not affected by this specific path. This issue is reported as fixed in version 8.1.0.1dCVE-2026-75953—4.7%
——1Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address.3dCVE-2026-733867.5 ALT16.0%
——5Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.2dCVE-2026-733847.5 ALT16.0%
——5Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.2dCVE-2026-740085.3 MED15.4%
——5Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions.2dCVE-2026-664637.5 ALT23.0%
——7Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.8d