SiYuan versions through 3.7.2 contain a critical SQL injection vulnerability, tracked as CVE-2026-69084, in the /api/search/searchEmbedBlock endpoint. The flaw allows attacker-controlled SQL to be passed directly to the main read-write siyuan.db database handle without single-statement, read-only, or administrative restrictions, creating a path to unauthorized database access and manipulation.
The endpoint is protected only by CheckAuth, which means it can be reached by users holding the publish RoleReader token and, in some deployments, by anonymous users when publish authentication is disabled. Because the underlying database driver permits stacked statements, attackers can read and modify content across all opened cleartext notebooks, although encrypted per-box notebooks are not exposed through this issue. The vulnerability is classified as CWE-89 and was fixed in SiYuan 3.7.3.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE entry states that disclosure@vulncheck.com received the new CVE on August 3, 2026, for the SiYuan SQL injection issue. The vulnerability was tracked as CVE-2026-69084 and associated with advisory GHSA-vh22-h7hf-www7.
SiYuan addressed a SQL injection flaw in the /api/search/searchEmbedBlock endpoint in version 3.7.3. The issue affected versions up to and including 3.7.2 and could allow reading and modifying content in opened cleartext notebooks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourcecvefeed.io
Open sourcevulncheck.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.