SiYuan < v3.7.3: Critical SQL Injection Vulnerabilities Confirmed
SiYuan versions before v3.7.3 contain SQL injection vulnerabilities that allow attackers to execute arbitrary SQL on the asset-content database. Users of affected versions should upgrade immediately.
What happened
SiYuan versions before v3.7.3 are affected by multiple critical SQL injection vulnerabilities (CVE-2026-69083, CVE-2026-69084, CVE-2026-69085) in various endpoints. These vulnerabilities allow unauthenticated attackers to execute arbitrary SQL statements on the read-write asset-content database, enabling them to read, modify, or delete cross-notebook data. The vulnerabilities are due to unescaped method parameters, REGEXP clauses, and direct concatenation of user-supplied input into SQL statements without proper escaping or parameter binding. The CVSS score for these vulnerabilities is 10.0, indicating a critical severity level. To mitigate these vulnerabilities, users should upgrade to SiYuan v3.7.3 or later.
How 0Day mitigates this
siyuan is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.