A critical SQL injection vulnerability (CVE-2026-69083) has been identified in SiYuan versions before v3.7.3. The flaw exists in the fullTextSearchAssetContent endpoint, which is accessible to unauthenticated users and RoleReader tokens. Attackers can exploit this by injecting malicious SQL through unescaped method parameters and REGEXP clauses, enabling read, write, and delete operations on the read-write asset-content database. This allows unauthorized access to cross-notebook data, including potential data exfiltration, modification, or destruction. All SiYuan instances running versions earlier than v3.7.3 are affected. Given the CVSS score of 10.0 and the risk of full database compromise, immediate remediation is required. Users should upgrade to v3.7.3 or later to mitigate this vulnerability. No workarounds are available for this high-severity issue.
CRITICAL
CVSS 10.0
CVE-2026-69083
2026-08-16
Critical SQL Injection Vulnerability in SiYuan (CVE-2026-69083)
SiYuan versions prior to v3.7.3 contain a critical SQL injection flaw in the fullTextSearchAssetContent endpoint, allowing unauthenticated attackers to execute arbitrary SQL queries and manipulate cross-notebook data.