CVE-2026-59834
published 2026-07-09CVE-2026-59834: SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST /api/search/fullTextSearchBlock concatenates…
PriorityP351high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.51%
42.4th percentile
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST /api/search/fullTextSearchBlock concatenates attacker-controlled paths values into SQL predicates used by non-SQL search modes, allowing an unauthenticated publish visitor to inject a UNION SELECT and return rows from hidden documents by projecting an allowed visible box and path. This issue is fixed in versions 3.7.1.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | siyuan-note_siyuan_kernel | >= 0 < 0.0.0-20260704035518-d0f0fe146fb0 | 0.0.0-20260704035518-d0f0fe146fb0 |
| siyuan-note | siyuan | < 3.7.1 | 3.7.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content
ghsa·2026-09-02
CVE-2026-59834 [HIGH] CWE-89 SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content
SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content
## Summary
Siyuan's block search endpoint concatenates attacker-controlled `paths[]` values into SQL predicates used by non-SQL search modes. Through Siyuan's publish service, an unauthenticated visitor is forwarded to the kernel with a reader-role token and can reach `POST /api/search/fullTextSearchBlock`.
An attacker can inject a `UNION SELECT` through `paths[]` and return rows from hidden documents while projecting an allowed visible `box` and `path`. The post-query publish access filter trusts the projected `box` and `path`, so the injected hidden row is returned to the publish visitor.
## Affected Code
The API blocks explicit SQL search mode for non-admin users, but allows other search methods to use call
VulDB
siyuan-note SiYuan up to 3.7.0 Block Search Endpoint fullTextSearchBlock paths sql injection
vuldb·2026-07-10·CVSS 7.5
CVE-2026-59834 [HIGH] siyuan-note SiYuan up to 3.7.0 Block Search Endpoint fullTextSearchBlock paths sql injection
A vulnerability was found in siyuan-note SiYuan up to 3.7.0 and classified as critical. Impacted is an unknown function of the file /api/search/fullTextSearchBlock of the component Block Search Endpoint. Such manipulation of the argument paths leads to sql injection.
This vulnerability is referenced as CVE-2026-59834. It is possible to launch the attack remotely. No exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/siyuan-note/siyuan/commit/57bcad4b331836880bfe6be25d4180bdcf10db0dhttps://github.com/siyuan-note/siyuan/commit/d0f0fe146fb07d594fcadc4f48d4f7c30ac01d1ehttps://github.com/siyuan-note/siyuan/releases/tag/v3.7.1https://github.com/siyuan-note/siyuan/security/advisories/GHSA-h89q-4j2h-7h88https://github.com/siyuan-note/siyuan/security/advisories/GHSA-h89q-4j2h-7h88
2026-07-09
Published