CVE-2026-69083: SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Att
SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Attackers can execute arbitrary SQL on the read-write asset-content database via unescaped method parameters and REGEXP clauses to read, modify, or delete cross-notebook data.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-69083
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-69083 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for SiYuan
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-69086: SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attr…nvd · 2026-08-03
- criticalCVE-2026-69085: SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs en…nvd · 2026-08-03
- criticalCVE-2026-69084: SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a cli…nvd · 2026-08-03
- highCVE-2026-68587: SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadin…nvd · 2026-08-03
- highCVE-2026-68586: SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackme…nvd · 2026-08-03
- mediumCVE-2026-68585: SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/ge…nvd · 2026-08-03
More from NVD Recent CVEs
- mediumCVE-2026-8508: An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S…2026-08-04
- highCVE-2026-6837: A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel …2026-08-04
- mediumCVE-2026-18720: A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown co…2026-08-04
- mediumCVE-2026-17614: A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileReposito…2026-08-04
- mediumCVE-2026-18719: A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the fil…2026-08-04