PT-2026-52109 · Siyuan · Siyuan

CVE-2026-54068

·

Published

2026-06-24

·

Updated

2026-07-30

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.7.0
Description The /api/icon/getDynamicIcon endpoint is excluded from authentication. When this endpoint is called with type=8 and a valid block id parameter, it invokes the RenderDynamicIconContentTemplate function, which executes a Go template containing the querySQL() and queryBlocks() functions. These functions allow the execution of arbitrary SELECT statements against the SQLite database. An unauthenticated network-adjacent attacker with knowledge of a valid block ID can exfiltrate user note content, tags, asset references, and block attributes.
Recommendations Update SiYuan to version 3.7.0.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54068
GHSA-GCM7-57GF-953C
GO-2026-5958
OPENSUSE-SU-2026:21483-1

Affected Products

Siyuan