SiYuan has a security flaw
The flaw affects SiYuan versions older than v3.7.4 and has a security flaw.
- Severity
- CriticalCVSS 3.1 · 10.0
- Fix
- Fixed in 0.0.0-20260723004839-1a5b3431d5abFix recorded on Aug 26, 2026
- Affected versions
- before 0.0.0-20260723004839-1a5b3431d5ab
- Weakness
- CWE-89SQL Injection
- Exploit likelihood
- 0.25% in 30 daysEPSS, higher than 16% of known flaws
- Affects
- SiYuan
How it works
Because the query runs on the main read-write siyuan.db handle via a statement-stacking-capable driver, an attacker can execute arbitrary SQL, enabling cross-notebook read and write.
What to do
Check whether the installed SiYuan version is older than v3.7.4.
Update SiYuan to v3.7.4 or newer. Then verify the installed version.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Changed Impact crosses a security authority boundary
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact None No availability impact
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N Open in FIRST.org calculatorReferences
- github.com · GHSA-q2vg-7qgx-x5fc vendor advisory
- nvd.nist.gov · CVE-2026-72811 vdb entry
- vulncheck.com · siyuan-before-sql-injection-via-backlink-search NVD GitHub Advisory
- github.com · commit 1a5b343 GitHub Advisory