SiYuan SQL Injection Vulnerability: Critical Risk to Database Integrity
SiYuan versions before 3.7.3 contain multiple SQL injection vulnerabilities that allow attackers to read and modify database content across all cleartext notebooks.
What happened
SiYuan versions before 3.7.3 are affected by critical SQL injection vulnerabilities tracked as CVE-2026-69083, CVE-2026-69084, and CVE-2026-69085. These vulnerabilities allow attackers to execute arbitrary SQL statements on the read-write database, enabling them to read, modify, or delete data across all cleartext notebooks. The vulnerabilities affect the fullTextSearchAssetContent, searchEmbedBlock, and filetree/searchDocs endpoints, which are reachable by unauthenticated users or those with publish RoleReader tokens under certain configurations. To mitigate these risks, it is recommended to upgrade to SiYuan v3.7.3 or later.
The CVSS scores for these vulnerabilities are 10.0, indicating a critical severity level. The vulnerabilities were confirmed by multiple independent sources, including the National Vulnerability Database (NVD). For detailed technical information and CVSS metrics, consult the primary sources linked in the threat data.
How 0Day mitigates this
siyuan is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.