CVE-2026-69084: SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no si
SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read-only, or admin restrictions. The endpoint is gated only by CheckAuth, making it reachable by the publish RoleReader token and by anonymous users when publish authentication is disabled. Because the underlying driver executes stacked statements, an attacker can read and modify content across all opened cleartext notebooks (encrypted per-box notebooks are excluded). Fixed in v3.7.3.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-69084
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-69084 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for SiYuan
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-69086: SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attr…nvd · 2026-08-03
- criticalCVE-2026-69085: SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs en…nvd · 2026-08-03
- criticalCVE-2026-69083: SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAsset…nvd · 2026-08-03
- highCVE-2026-68587: SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadin…nvd · 2026-08-03
- highCVE-2026-68586: SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackme…nvd · 2026-08-03
- mediumCVE-2026-68585: SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/ge…nvd · 2026-08-03
More from NVD Recent CVEs
- mediumCVE-2026-8508: An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S…2026-08-04
- highCVE-2026-6837: A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel …2026-08-04
- mediumCVE-2026-18720: A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown co…2026-08-04
- mediumCVE-2026-17614: A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileReposito…2026-08-04
- mediumCVE-2026-18719: A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the fil…2026-08-04