PT-2026-67406 · Siyuan · Siyuan

·

CVE-2026-69084

·

Published

2026-08-03

·

Updated

2026-09-10

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.7.3
Description The '/api/search/searchEmbedBlock' endpoint passes a client-supplied SQL statement directly to the main read-write siyuan.db handle without restrictions on single statements, read-only access, or administrative privileges. The endpoint is protected only by CheckAuth, allowing access via the publish RoleReader token or by anonymous users if publish authentication is disabled. Since the driver supports stacked statements (the ability to execute multiple SQL commands in a single call), an attacker can read and modify content across all opened cleartext notebooks, although encrypted per-box notebooks are not affected.
Recommendations Update to version 3.7.3.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-69084
GHSA-P2X7-4C4P-8WH6
GHSA-VH22-H7HF-WWW7
GO-2026-6377

Affected Products

Siyuan