CVE-2026-100644: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in siyuan-note siyuan
SiYuan before v3.8.4 contains a SQL injection vulnerability in the graph query endpoint where the dailyNoteSavePath parameter is concatenated into SQL without escaping. Unauthenticated attackers on published sites with auth disabled can inject SQL via UNION SELECT to extract arbitrary database rows from all notebooks.
AI Analysis
Technical Summary
CVE-2026-100644 describes a SQL injection vulnerability in SiYuan note-taking software before version 3.8.4. The flaw exists in the graph query endpoint where the dailyNoteSavePath parameter is directly concatenated into SQL queries without sanitization or escaping. This improper neutralization of special elements enables unauthenticated attackers, particularly on published sites with authentication disabled, to perform UNION SELECT injections. Exploitation can lead to unauthorized disclosure of arbitrary database rows across all notebooks managed by the software.
Potential Impact
An attacker can exploit this vulnerability to extract arbitrary data from the application's database without authentication. This compromises confidentiality of all notebooks stored in the system. The vulnerability has a high CVSS 4.0 score of 8.7, indicating a severe risk of data exposure via remote, unauthenticated access with no user interaction required.
Mitigation Recommendations
Upgrade SiYuan to version 3.8.4 or later, where this SQL injection vulnerability has been fixed. Until then, ensure that published sites have authentication enabled to prevent unauthenticated access. No other mitigations are specified. Patch status is confirmed by the version boundary indicating the fix in 3.8.4.
CVE-2026-100644: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in siyuan-note siyuan
Description
SiYuan before v3.8.4 contains a SQL injection vulnerability in the graph query endpoint where the dailyNoteSavePath parameter is concatenated into SQL without escaping. Unauthenticated attackers on published sites with auth disabled can inject SQL via UNION SELECT to extract arbitrary database rows from all notebooks.
CVSS v4.0
Score 8.7high
Affected software
siyuan-note
siyuan
pkg:github/siyuan-note/siyuanRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-100644 describes a SQL injection vulnerability in SiYuan note-taking software before version 3.8.4. The flaw exists in the graph query endpoint where the dailyNoteSavePath parameter is directly concatenated into SQL queries without sanitization or escaping. This improper neutralization of special elements enables unauthenticated attackers, particularly on published sites with authentication disabled, to perform UNION SELECT injections. Exploitation can lead to unauthorized disclosure of arbitrary database rows across all notebooks managed by the software.
Potential Impact
An attacker can exploit this vulnerability to extract arbitrary data from the application's database without authentication. This compromises confidentiality of all notebooks stored in the system. The vulnerability has a high CVSS 4.0 score of 8.7, indicating a severe risk of data exposure via remote, unauthenticated access with no user interaction required.
Mitigation Recommendations
Upgrade SiYuan to version 3.8.4 or later, where this SQL injection vulnerability has been fixed. Until then, ensure that published sites have authentication enabled to prevent unauthenticated access. No other mitigations are specified. Patch status is confirmed by the version boundary indicating the fix in 3.8.4.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-26T02:32:35.659Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab7c9a7f7a7c5410652fd2c
Added to database: 09/26/2026, 13:33:27 UTC
Last enriched: 09/26/2026, 14:03:41 UTC
Last updated: 09/27/2026, 03:21:56 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.