
Article5 min read
SiYuan fixes prompt-injection path to SSH keys and cloud credentials
CVE-2026-82233 shows how an AI agent’s ordinary upload tool can turn hidden instructions and an approved tool call into sensitive local-file exposure.
CVE-2026-82233 let SiYuan’s AI agent copy sensitive local files through MCP, showing why tool approvals need action-level policy.
Read article