CVE-2026-101091
published 2026-09-28CVE-2026-101091: SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db. Attackers can craft malicious…
PriorityP339high7.1CVSS 3.1
AVNACLPRNUIRSUCHILAN
EPSS
0.26%
15.7th percentile
SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db. Attackers can craft malicious .sy documents with non-read-only SQL statements that execute automatically during background indexing, rendering, or export operations without authentication.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siyuan-note | siyuan | < 3.8.4 | 3.8.4 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
nvdv4.07.1HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Siyuan Note SiYuan up to 3.8.3 Block Query Embed siyuan.db sql injection
vuldb·2026-09-29·CVSS 7.1
CVE-2026-101091 [HIGH] Siyuan Note SiYuan up to 3.8.3 Block Query Embed siyuan.db sql injection
A vulnerability classified as critical was found in Siyuan Note SiYuan up to 3.8.3. The affected element is an unknown function of the file siyuan.db of the component Block Query Embed. Executing a manipulation can lead to sql injection.
This vulnerability appears as CVE-2026-101091. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
GHSA
SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db.
ghsa_unreviewed·2026-09-29
CVE-2026-101091 [HIGH] CWE-89 SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db.
SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db. Attackers can craft malicious .sy documents with non-read-only SQL statements that execute automatically during background indexing, rendering, or export operations without authentication.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/siyuan-note/siyuan/commit/e8ace0c89182c7ee1a1298ff2a849bb6a83dfdechttps://github.com/siyuan-note/siyuan/security/advisories/GHSA-67p9-hm94-xwf3https://www.vulncheck.com/advisories/siyuan-before-3.8.4-sql-injection-via-block-query-embedhttps://github.com/siyuan-note/siyuan/security/advisories/GHSA-67p9-hm94-xwf3
2026-09-28
Published