CVE-2026-69085: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in siyuan-note siyuan
SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no escaping or parameter binding. The endpoint is reachable by a publish RoleReader token, or unauthenticated when publish mode is enabled with Publish.Auth.Enable set to false. Because the statement executes on a read-write SQLite handle via a driver that supports stacked (semicolon-separated) statements, an attacker can read and modify database content across all cleartext (non-encrypted) notebooks on the instance.
AI Analysis
Technical Summary
CVE-2026-69085 describes a SQL injection vulnerability in SiYuan note-taking software before version 3.7.3. The issue exists in the /api/filetree/searchDocs endpoint, where user-supplied input in the keyword parameter is concatenated directly into SQL statements without escaping or parameterization. Because the underlying SQLite driver supports stacked SQL statements separated by semicolons, an attacker can execute arbitrary SQL commands, leading to unauthorized reading and modification of database content in all unencrypted notebooks. The endpoint is accessible with a publish RoleReader token or without authentication if publish mode authentication is disabled via Publish.Auth.Enable set to false. This vulnerability is critical with a CVSS 4.0 score of 9.9.
Potential Impact
Successful exploitation allows an attacker to read and modify the database content of all cleartext notebooks on the affected SiYuan instance. This can lead to unauthorized data disclosure and data tampering. The vulnerability requires no privileges or user interaction if publish mode authentication is disabled, increasing the attack surface significantly.
Mitigation Recommendations
A fixed version 3.7.3 of SiYuan is available that addresses this SQL injection vulnerability. Users should upgrade to version 3.7.3 or later to remediate this issue. Until upgraded, ensure that publish mode authentication is enabled (Publish.Auth.Enable set to true) to reduce exposure. Patch status is confirmed by the existence of fixed version 3.7.3.
CVE-2026-69085: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in siyuan-note siyuan
Description
SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no escaping or parameter binding. The endpoint is reachable by a publish RoleReader token, or unauthenticated when publish mode is enabled with Publish.Auth.Enable set to false. Because the statement executes on a read-write SQLite handle via a driver that supports stacked (semicolon-separated) statements, an attacker can read and modify database content across all cleartext (non-encrypted) notebooks on the instance.
CVSS v4.0
Score 9.9critical
Affected software
pkg:github/siyuan-note/siyuanRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-69085 describes a SQL injection vulnerability in SiYuan note-taking software before version 3.7.3. The issue exists in the /api/filetree/searchDocs endpoint, where user-supplied input in the keyword parameter is concatenated directly into SQL statements without escaping or parameterization. Because the underlying SQLite driver supports stacked SQL statements separated by semicolons, an attacker can execute arbitrary SQL commands, leading to unauthorized reading and modification of database content in all unencrypted notebooks. The endpoint is accessible with a publish RoleReader token or without authentication if publish mode authentication is disabled via Publish.Auth.Enable set to false. This vulnerability is critical with a CVSS 4.0 score of 9.9.
Potential Impact
Successful exploitation allows an attacker to read and modify the database content of all cleartext notebooks on the affected SiYuan instance. This can lead to unauthorized data disclosure and data tampering. The vulnerability requires no privileges or user interaction if publish mode authentication is disabled, increasing the attack surface significantly.
Mitigation Recommendations
A fixed version 3.7.3 of SiYuan is available that addresses this SQL injection vulnerability. Users should upgrade to version 3.7.3 or later to remediate this issue. Until upgraded, ensure that publish mode authentication is enabled (Publish.Auth.Enable set to true) to reduce exposure. Patch status is confirmed by the existence of fixed version 3.7.3.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-03T10:42:57.736Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7098b1bf32cb7a34a8231c
Added to database: 08/03/2026, 13:33:37 UTC
Last enriched: 08/03/2026, 13:49:11 UTC
Last updated: 08/03/2026, 16:29:28 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.