


Perceptive Security
SOC/SIEM Consultancy

SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish Ro…
Published:
2 augustus 2026 om 22:00:00
Alert date:
3 augustus 2026 om 15:06:10
Source:
nvd.nist.gov
Web Technologies, Database & Storage, Zero-Day Vulnerabilities
SiYuan versions prior to v3.7.3 are affected by SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint. The vulnerability is reachable by unauthenticated users as well as those with publish RoleReader tokens. Attackers can exploit unescaped method parameters and REGEXP clauses to execute arbitrary SQL queries against the read-write asset-content database. Successful exploitation allows reading, modifying, or deleting cross-notebook data. The issue has been patched in SiYuan v3.7.3. References are available via the NVD, a GitHub security advisory, and VulnCheck.
Technical details
Mitigation steps:
Affected products:
SiYuan before v3.7.3
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-69083
https://github.com/siyuan-note/siyuan/security/advisories/GHSA-fph3-ghq9-vw66
https://www.vulncheck.com/advisories/siyuan-before-sql-injection-via-fulltextsearchassetcontent
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
