Sploitus

CVE-2026-69084

1 known exploit for CVE-2026-69084

SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read-only, or admin restrictions. The endpoint is gated only by CheckAuth, making it reachable by the publish RoleReader token and by anonymous users when publish authentication is disabled. Because the underlying driver executes stacked statements, an attacker can read and modify content across all opened cleartext notebooks (encrypted per-box notebooks are excluded). Fixed in v3.7.3.

Affected products
Siyuan
CVSS 3.1
10.0 CRITICAL
EPSS
0.3% (21th percentile)
Weakness
CWE-89
NVD status
Received
Published
2026-08-03
CVE-2026-69084 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-69084

Proof-of-concept code and exploit modules indexed by Sploitus