A AegiFlow
CRITICALCVSS 10.0EPSS 1.1%

CVE-2026-69084

CVE-2026-69084 updated by NVD

Published
2026-09-03
Modified
2026-09-03
EPSS percentile
64%
Sources
github-advisory, nvd

Summary

SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read-only, or admin restrictions. The endpoint is gated only by CheckAuth, making it reachable by the publish RoleReader token and by anonymous users when publish authentication is disabled. Because the underlying driver executes stacked statements, an attacker can read and modify content across all opened cleartext notebooks (encrypted per-box notebooks are excluded). Fixed in v3.7.3.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/siyuan-note/siyuan/kernel0.0.0-20260721002947-23a17d44b5f3

Remediation: Upgrade to 0.0.0-20260721002947-23a17d44b5f3 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.