cbcvebase.
CVE-2026-59834
published 2026-07-09

CVE-2026-59834: SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST /api/search/fullTextSearchBlock concatenates…

PriorityP351high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.51%
42.4th percentile
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST /api/search/fullTextSearchBlock concatenates attacker-controlled paths values into SQL predicates used by non-SQL search modes, allowing an unauthenticated publish visitor to inject a UNION SELECT and return rows from hidden documents by projecting an allowed visible box and path. This issue is fixed in versions 3.7.1.

Affected

2 ranges
VendorProductVersion rangeFixed in
github.comsiyuan-note_siyuan_kernel>= 0 < 0.0.0-20260704035518-d0f0fe146fb00.0.0-20260704035518-d0f0fe146fb0
siyuan-notesiyuan< 3.7.13.7.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.