CVE-2026-60083 | SiYuan-Note SiYuan up to 3.7.x MCP File Tool publishAccess.json missing encryption

SecurityVulns

A vulnerability marked as problematic has been reported in SiYuan-Note SiYuan up to 3.7.x. This issue affects some unknown processing of the file data/.siyuan/publishAccess.json of the component MCP File Tool. This manipulation causes missing encryption of sensitive data.

This vulnerability is handled as CVE-2026-60083. The attack can be initiated remotely. There is not any exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More