Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
SiYuan can let attackers read and modify notebooks
published 21 days ago
Summary
Versions of the SiYuan note‑taking tool up to 3.7.2 let a user enter specially crafted text that can trick the system into running its own commands. This could allow someone to view or change any notebook stored in the application. Upgrade to version 3.7.4 or later to fix the problem.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Go | siyuan-note | github.com/siyuan-note/siyuan/kernel | All versions |
Original advisory text
Duplicate Advisory: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle
## Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-q2vg-7qgx-x5fc. This link is maintained to preserve external references.
## Original Description
SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and the client-supplied keyword into a SQL MATCH/search statement while escaping only the double-quote character and not the single quote. A single quote in the client keyword (first-order, reachable by an anonymous or RoleReader user on the publish surface) or in stored document metadata (second-order) breaks out of the string literal. Because the query runs on the main read-write siyuan.db handle via a statement-stacking-capable driver, an attacker can execute arbitrary SQL, enabling cross-notebook read and write. Fixed in v3.7.4.
This advisory has been withdrawn because it is a duplicate of GHSA-q2vg-7qgx-x5fc. This link is maintained to preserve external references.
## Original Description
SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and the client-supplied keyword into a SQL MATCH/search statement while escaping only the double-quote character and not the single quote. A single quote in the client keyword (first-order, reachable by an anonymous or RoleReader user on the publish surface) or in stored document metadata (second-order) breaks out of the string literal. Because the query runs on the main read-write siyuan.db handle via a statement-stacking-capable driver, an attacker can execute arbitrary SQL, enabling cross-notebook read and write. Fixed in v3.7.4.
Severity
9.1
Critical
CVSS 3.1: 10.0 (OSV)
CVSS 4.0: 9.1 (OSV)
Type
CWE-89SQL Injection
Timeline
Published14 Aug 2026
Updated3 Sep 2026
First seen3 Sep 2026
Sources
GHSA-p8cp-78hp-wmq8 · OSV
Monitor software like this
Free during beta