PT-2026-57009 · Siyuan · Siyuan

CVE-2026-59834

·

Published

2026-07-09

·

Updated

2026-09-10

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.7.1
Description An unauthenticated publish visitor can perform a UNION SELECT injection via the block search endpoint 'POST /api/search/fullTextSearchBlock'. The issue occurs because the endpoint concatenates attacker-controlled paths values into SQL predicates used by non-SQL search modes, allowing the retrieval of rows from hidden documents by projecting an allowed visible box and path.
Recommendations Update to version 3.7.1.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59834
GHSA-H89Q-4J2H-7H88
GO-2026-6353

Affected Products

Siyuan