SiYuan has a security flaw

Published September 3, 2026 CVE-2026-72811

The flaw affects SiYuan versions older than v3.7.4 and has a security flaw.

Severity
CriticalCVSS 3.1 · 10.0
Fix
Fixed in 0.0.0-20260723004839-1a5b3431d5abFix recorded on Aug 26, 2026
Affected versions
before 0.0.0-20260723004839-1a5b3431d5ab
Weakness
CWE-89SQL Injection
Exploit likelihood
0.25% in 30 daysEPSS, higher than 16% of known flaws
Affects
SiYuan

How it works

Because the query runs on the main read-write siyuan.db handle via a statement-stacking-capable driver, an attacker can execute arbitrary SQL, enabling cross-notebook read and write.

What to do

Check whether the installed SiYuan version is older than v3.7.4.

Update SiYuan to v3.7.4 or newer. Then verify the installed version.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Changed Impact crosses a security authority boundary
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact None No availability impact
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N Open in FIRST.org calculator