PT-2026-99315 · Siyuan · Siyuan

·

CVE-2026-100644

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.8.4
Description An issue exists in the graph query endpoint where the dailyNoteSavePath parameter is concatenated into a SQL query without proper escaping. This allows unauthenticated attackers on published sites with authentication disabled to perform a SQL injection using UNION SELECT to extract arbitrary database rows from all notebooks.
Recommendations Update to version 3.8.4 or later. Avoid using the dailyNoteSavePath parameter in the graph query endpoint until the update is applied.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100644
GHSA-XR4H-J7CG-Q8PC

Affected Products

Siyuan