ADVISORYHIGH12d ago · Sep 4, 2026

SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf

CVE: This vulnerability corresponds to CVE-2026-72794. Summary /api/system/getConf returns Conf.CookieKey, the key used to sign the server's session cookies in its response body. The endpoint is registered with CheckAuth only, so the field reaches the…

Read it at github.com/siyuan-note/siyuan/kernel

More advisory

4 itemsEverything on the wire ›
ADVISORY
CRITICAL: @zereight/mcp-gitlab — @zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover
The SSE transport mode (SSE=true) exposes all MCP tools without any authentication. The uploadmarkdown tool reads arbitrary files from the server's local filesystem via an unsanitized filepath parameter and uploads them to a GitLab project.…
@zereight/mcp-gitlab
7h
ADVISORY
HIGH: @zereight/mcp-gitlab — @zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
@zereight/mcp-gitlab exposes GitLab to an LLM agent while relying on read-only mode, a project allow-list, and transport auth as its safety controls. Five defects defeat those controls. Under the MCP threat model, tool-call arguments/content can be…
@zereight/mcp-gitlab
22h
ADVISORY
CRITICAL: @zereight/mcp-gitlab — @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
Server-Side Request Forgery via X-GitLab-API-URL Header Allows Credential Theft Affected - Repository: zereight/gitlab-mcp - Affected versions: All versions through commit 74a8c83 - Patched versions: None at time of report Severity High. CVSS v3.1 8.5…
@zereight/mcp-gitlab
1d
ADVISORY
HIGH: org.http4s:http4s-ember-server_2.12 — Http4s: DigestAuth nonce map grows unbounded
The DigestAuth server middleware's stale-nonce cleanup uses an inverted comparison: it removes fresh nonces and stops at the first stale one. Because a new nonce is created for every unauthenticated challenge, an attacker can drive the nonce map to grow…
org.http4s:http4s-ember-server_2.12
1d