Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-72811: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in siyuan-note siyuan

0
Critical
Published: 08/14/2026 (08/14/2026, 11:35:24 UTC)
Source: CVE Database V5
Vendor/Project: siyuan-note
Product: siyuan

Description

SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and the client-supplied keyword into a SQL MATCH/search statement while escaping only the double-quote character and not the single quote. A single quote in the client keyword (first-order, reachable by an anonymous or RoleReader user on the publish surface) or in stored document metadata (second-order) breaks out of the string literal. Because the query runs on the main read-write siyuan.db handle via a statement-stacking-capable driver, an attacker can execute arbitrary SQL, enabling cross-notebook read and write. Fixed in v3.7.4.

CVSS v4.0

Score 9.9critical

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
None
Subsq. Confidentiality
High
Subsq. Integrity
High
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

Affected software

GitHub Actionsmore threats →ai
siyuan-note/siyuan
pkg:github/siyuan-note/siyuan
Affected versions
<3.7.4

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 12:26:07 UTC

Technical Analysis

SiYuan versions <= 3.7.2 have a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go). The vulnerability is due to improper neutralization of special elements in SQL commands: the application concatenates stored block metadata and client-supplied keywords into a SQL MATCH/search statement, escaping only double quotes but not single quotes. This allows an attacker, including anonymous or RoleReader users, to inject SQL via single quotes in the keyword or stored metadata. The query executes on the main read-write siyuan.db handle using a driver that supports statement stacking, enabling arbitrary SQL execution and cross-notebook read/write capabilities. The vulnerability is fixed in version 3.7.4.

Potential Impact

An attacker can execute arbitrary SQL commands on the main read-write database, potentially reading and modifying data across notebooks. This can lead to data compromise, unauthorized data manipulation, and loss of data integrity. The vulnerability is exploitable without authentication (anonymous users) and requires no user interaction, making it highly severe.

Mitigation Recommendations

Upgrade SiYuan to version 3.7.4 or later, where this SQL injection vulnerability is fixed. No other mitigations are specified or recommended by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-08-10T15:11:49.794Z
Cvss Version
4.0
State
PUBLISHED
Remediation Level
null

Threat ID: 6a7f0282bf8831d539fec754

Added to database: 08/14/2026, 11:56:50 UTC

Last enriched: 08/14/2026, 12:26:07 UTC

Last updated: 08/14/2026, 20:05:05 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses