A critical SQL injection flaw tracked as CVE-2026-72811 affects SiYuan versions before 3.7.4, allowing remote attackers to execute arbitrary SQL through the application's backlink and mention search functionality. The bug stems from unsafe construction of a SQL MATCH query in kernel/model/backlink.go, where stored block metadata and user-supplied keywords are concatenated into a search statement with incomplete escaping, letting attackers break out of string literals using single quotes.
The vulnerability is remotely reachable through the publish surface, including by anonymous users or users with RoleReader access, and can also be exploited as a second-order injection via stored document metadata. Because the query runs against the main read-write siyuan.db handle and the database driver supports statement stacking, successful exploitation can result in arbitrary SQL execution and cross-notebook read and write access. The issue is classified as CWE-89, carries a CVSS v3.1 score of 10.0 and CVSS v4.0 score of 9.9, and is fixed in SiYuan 3.7.4.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The vulnerability record for CVE-2026-72811 was published, describing a critical SQL injection flaw in SiYuan's backlink search functionality. The advisory assigned the issue critical severity and referenced GitHub Security Advisory GHSA-q2vg-7qgx-x5fc.
SiYuan addressed CVE-2026-72811, a critical SQL injection vulnerability in the backlink/mention search query, in version 3.7.4. The issue affected versions prior to 3.7.4 and could allow arbitrary SQL execution with cross-notebook read and write access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.