SQL Injection Vulnerability in SiYuan by SiYuan Notes
CVE-2026-69084
9.9CRITICAL
What is CVE-2026-69084?
Versions of SiYuan up to v3.7.2 are susceptible to a SQL injection attack through the /api/search/searchEmbedBlock endpoint. This vulnerability allows an attacker to send a malicious SQL statement, which is executed directly against the siyuan.db database without adequate validation or restrictions. The lack of proper access controls means that both authenticated users with the RoleReader token and anonymous users, when publish authentication is disabled, can exploit this vulnerability. Consequently, this can lead to unauthorized access and manipulation of content across all unencrypted notebooks. The issue has been addressed in version 3.7.3.
Affected Version(s)
siyuan 0 < 3.7.3
siyuan 3.7.3
