Skip to main content
EPSS 0.4%top 65%

CVE-2026-72811: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in siyuan-note siyuan

0
Critical
Published: 09/03/2026 (09/03/2026, 22:27:50 UTC)
Source: CVE Database V5
Vendor/Project: siyuan-note
Product: siyuan

Description

**CVE:** This vulnerability corresponds to [CVE-2026-72811](https://nvd.nist.gov/vuln/detail/CVE-2026-72811). ### Summary The backlink/mention search query (`kernel/model/backlink.go`) concatenates stored block metadata (title, name, alias, anchor text) and the client-supplied keyword into a SQL `MATCH`/search statement, escaping only the double-quote character (`"`) and not the single quote (`'`). A single quote in either the client keyword or in stored document metadata breaks out of the string literal. The query runs on the main read-write `siyuan.db` handle through a statement-stacking-capable driver. This yields two vectors: - **First-order:** a client-supplied keyword containing `'` injects directly. This path is reachable by an anonymous reader on the publish surface. - **Second-order:** a document whose title/name/alias contains `'` is stored safely (indexing uses parameterized inserts) but detonates when that stored value is later concatenated into the backlink query including on another user's kernel that has ingested the malicious document. ### Details **Storage is safe; reuse is not.** Indexing INSERTs (`kernel/sql/upsert.go`) are parameterized (`(?,?,…)` with bound arguments for `Name`/`Content`/`Markdown`/`IAL`), so malicious `.sy` content is stored intact and safely. The injection is in the *reuse* path: the backlink/mention MATCH query (`kernel/model/backlink.go`, around line 980) builds its condition by concatenating the stored title/name/alias/anchor and the client keyword, applying only `"`→escaping and not `'`. A `'` in either source terminates the literal and lands in SQL context. **Sink / handle.** The concatenated statement reaches `SelectBlocksRawStmtNoParse` → `query()` on the global read-write `siyuan.db` handle (DSN has no `mode=ro`/`_query_only`), driven by the vendored `88250/go-sqlite3` fork whose connection `query` loops over `;`-separated statements (stacking possible). Ceiling is arbitrary SQL cross-notebook read and write. **Route / auth tier.** The backlink/mention family (`getBacklink`, `getBacklink2`, `getBacklinkDoc`, `getBackmentionDoc`) is `CheckAuth`-only, so the first-order client-keyword vector is reachable by the publish `RoleReader` token and by the anonymous account when `Publish.Auth.Enable` is `false`. **Scope of the injection surface (confirmed the only second-order sink).** A sweep of the query paths that reuse stored content confirmed this is the sole injectable reuse sink: indexing INSERTs are parameterized, tag search uses `content LIKE ?` with pattern escaping, virtual refs use in-memory matching (no SQL), `IN(...)` joins use node-IDs/hex-hashes/ROWIDs (no quote surface), and the graph name/content filter escapes `'`. Only the backlink/mention MATCH path concatenates with `'` unescaped. ### Proof of Concept Reproduced on a local instance (SiYuan running locally, publish mode enabled on port 6808, publish Basic Auth disabled). Strictly non-destructive verification, a syntax-error probe and a stored-value observation; no UNION exfiltration, no write, no DDL. **First-order (client keyword), anonymous reader on port 6808:** ``` POST http://127.0.0.1:6808/api/ref/getBacklink2 {"id":"<block id>","k":"a'b","mk":""} ``` The keyword `a'b` reaches the concatenated `MATCH` condition and produces a SQL parse error, confirming the single quote breaks out of the literal and the client keyword lands in SQL context. **Second-order (stored title), setup via admin then observed anonymously:** A document whose title contains a single quote e.g. `("locked-doc")` style metadata is stored safely by the parameterized indexer, then appears at the exact unescaped position in the backlink query when that document participates in a backlink/mention lookup, breaking the query the same way. This demonstrates that stored document metadata detonates on reuse, independent of the client keyword. Verification was limited to the syntax-error probe and the stored-value position observation; no exfiltration or write statement was executed. Full reproduction detail available privately on request. ### Impact **First-order:** an anonymous reader (publish mode with auth disabled) or any publish `RoleReader` injects arbitrary SQL into the backlink/mention query via the keyword parameter, on the read-write main handle: cross-notebook read disclosure and, via statement stacking, write and `ATTACH`. This is the same anonymous-arbitrary-SQL severity as the search/embed injection findings, on a different sink. **Second-order:** a document whose title/name/alias contains injection content is stored safely but executes when that stored value is concatenated into the backlink query. This fires on any kernel that has ingested the malicious document for example via a shared or imported `.sy` file, sync, or an opened `.sy.zip`. The precondition here is content delivery into the victim workspace (not a direct anonymous request), so it is a distinct, delivery-dependent threat model from the f

CVSS v4.0

Score 9.9critical

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
None
Subsq. Confidentiality
High
Subsq. Integrity
High
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

Affected software

siyuan-note

siyuan

Affected versions
>=0 <3.7.4
GitHub Actionsmore threats →ai
siyuan-note/siyuan
pkg:github/siyuan-note/siyuan
Affected versions
<3.7.4

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 12:26:07 UTC

Technical Analysis

SiYuan versions <= 3.7.2 have a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go). The vulnerability is due to improper neutralization of special elements in SQL commands: the application concatenates stored block metadata and client-supplied keywords into a SQL MATCH/search statement, escaping only double quotes but not single quotes. This allows an attacker, including anonymous or RoleReader users, to inject SQL via single quotes in the keyword or stored metadata. The query executes on the main read-write siyuan.db handle using a driver that supports statement stacking, enabling arbitrary SQL execution and cross-notebook read/write capabilities. The vulnerability is fixed in version 3.7.4.

Potential Impact

An attacker can execute arbitrary SQL commands on the main read-write database, potentially reading and modifying data across notebooks. This can lead to data compromise, unauthorized data manipulation, and loss of data integrity. The vulnerability is exploitable without authentication (anonymous users) and requires no user interaction, making it highly severe.

Mitigation Recommendations

Upgrade SiYuan to version 3.7.4 or later, where this SQL injection vulnerability is fixed. No other mitigations are specified or recommended by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-08-10T15:11:49.794Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6a7f0282bf8831d539fec754

Added to database: 08/14/2026, 11:56:50 UTC

Last enriched: 08/14/2026, 12:26:07 UTC

Last updated: 09/29/2026, 01:47:44 UTC

Views: 55

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses