CVE-2026-69084 is a SQL injection vulnerability in SiYuan through version 3.7.2. The searchEmbedBlock API accepts a client-controlled SQL statement and submits it verbatim to SiYuan's primary read-write SQLite database handle. The affected path lacks single-statement, read-only, and administrator-role enforcement, while the SQLite driver permits stacked statements. This permits arbitrary database operations against data in opened cleartext notebooks.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python PoC for two critical SiYuan vulnerabilities: CVE-2026-69084 and CVE-2026-69085. The repository contains one executable script (CVE-2026-69084.py), a README with usage and verification notes, and a LICENSE file. The Python script is the clear entry point and implements HTTP POST interactions with SiYuan's API using urllib and a cookie jar for session handling. The main exploit capability targets /api/search/searchEmbedBlock. After optional authentication through /api/system/loginAuth, the script sends attacker-controlled JSON containing a stmt field directly to the vulnerable endpoint. The script supports arbitrary operator-supplied SQL, a non-destructive check mode using SELECT sqlite_version(), and a proof mode that performs CREATE TABLE and INSERT statements to demonstrate database write access. Because the vulnerability allows stacked or unrestricted SQL according to the repository description, the exploit can be used for broad database manipulation against siyuan.db, including read, create, insert, update, delete, and drop operations. The script also includes a secondary mode for CVE-2026-69085, sending a user-controlled keyword to /api/filetree/searchDocs to test SQL injection behavior. This path is less developed than the primary exploit and functions mainly as a basic injection test helper rather than a full exploitation workflow. Structurally, the code is straightforward: get_opener() initializes a cookie-aware opener, api_request() performs JSON POST requests and parses responses, login() authenticates if an auth code is provided, exploit_sql() drives the primary SQL execution primitive, check() performs a safe probe, proof() demonstrates persistent DB modification, and main() parses CLI arguments and dispatches modes. Overall, this is a real, functional exploit PoC rather than a detection-only script, with operational capability centered on authenticated or anonymously exposed web API abuse against vulnerable SiYuan instances.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated or publish-reader arbitrary SQL execution vulnerability in SiYuan's searchEmbedBlock API. The endpoint permits arbitrary, including stacked, SQL statements on the main read-write database, enabling cross-notebook cleartext data disclosure and modification; ATTACH-reachable file side effects are also possible. Encrypted notebooks are excluded, and default builds do not permit code execution through load_extension.
A critical arbitrary SQL execution vulnerability in SiYuan's searchEmbedBlock functionality, allowing execution of non-read-only or multi-statement SQL queries.
A critical arbitrary SQL execution vulnerability in SiYuan's searchEmbedBlock functionality, apparently affecting b3log/siyuan v3.7.2 and involving the /api/search/searchEmbedBlock endpoint.
A critical unauthenticated SQL injection vulnerability in SiYuan's /api/search/searchEmbedBlock endpoint that allows remote attackers to read and modify content across opened cleartext notebooks.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.