SQL Injection Vulnerability in SiYuan by SiYuan Team
CVE-2026-72807

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-72807?

The vulnerability in SiYuan prior to version 3.7.4 introduces a second-order SQL injection, particularly affecting attribute-view template columns. This flaw occurs in the queryBlocks function, which improperly executes unfiltered SQL through string substitution instead of employing secure parameterized queries. Malicious actors can exploit this vulnerability by crafting specific SiYuan documents or packages, leading to the execution of arbitrary SQL commands upon import and rendering. This exposes sensitive data and allows unauthorized read and write access across user notebooks, posing significant threats to data integrity and security.

Affected Version(s)

siyuan 0 < 3.7.4

siyuan 3.7.4

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shirshakhtml
.