Inadequate Security Controls in SiYuan by SiYuan Team
CVE-2026-87808
8.7HIGH
What is CVE-2026-87808?
SiYuan versions prior to 3.8.2 exhibit a vulnerability where the read-only boundary is bypassed via the /api/search/fullTextSearchBlock endpoint. Although an administrator check was introduced, it failed to properly enforce the application's read-only state. This allows authenticated administrators to inject arbitrary SQL queries into the database when the workspace is set to read-only mode, potentially exposing sensitive data. The vulnerability was addressed in version 3.8.2.
Affected Version(s)
siyuan 0 < 3.8.2
siyuan 3.8.2
