SQL Injection Vulnerability in SiYuan by SiYuan Notes
CVE-2026-69084

9.9CRITICAL

Key Information:

Status
Vendor
CVE Published:
3 August 2026

What is CVE-2026-69084?

Versions of SiYuan up to v3.7.2 are susceptible to a SQL injection attack through the /api/search/searchEmbedBlock endpoint. This vulnerability allows an attacker to send a malicious SQL statement, which is executed directly against the siyuan.db database without adequate validation or restrictions. The lack of proper access controls means that both authenticated users with the RoleReader token and anonymous users, when publish authentication is disabled, can exploit this vulnerability. Consequently, this can lead to unauthorized access and manipulation of content across all unencrypted notebooks. The issue has been addressed in version 3.7.3.

Affected Version(s)

siyuan 0 < 3.7.3

siyuan 3.7.3

References

CVSS V4

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shirshakhtml
.