


Perceptive Security
SOC/SIEM Consultancy

SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenate…
Published:
2 augustus 2026 om 22:00:00
Alert date:
3 augustus 2026 om 15:06:10
Source:
nvd.nist.gov
Web Technologies, Database & Storage, Zero-Day Vulnerabilities
SiYuan versions before v3.7.3 contain a SQL injection vulnerability in the /api/filetree/searchDocs endpoint. The keyword parameter is directly concatenated into SQL queries without escaping or parameterized binding. The vulnerability is exploitable by users with a publish RoleReader token, or entirely unauthenticated when publish mode is enabled with Publish.Auth.Enable set to false. The underlying SQLite handle is read-write and the driver supports stacked (semicolon-separated) statements, allowing attackers to both read and modify database content. All cleartext (non-encrypted) notebooks on the affected instance are at risk. The fix was introduced in SiYuan v3.7.3. This vulnerability has been documented by NVD, GitHub Security Advisories, and VulnCheck.
Technical details
Mitigation steps:
Affected products:
SiYuan before v3.7.3
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-69085
https://github.com/siyuan-note/siyuan/security/advisories/GHSA-33jq-p8c2-q3q4
https://www.vulncheck.com/advisories/siyuan-before-sql-injection-via-searchdocs
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
