Description
SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db. Attackers can craft malicious .sy documents with non-read-only SQL statements that execute automatically during background indexing, rendering, or export operations without authentication.
Published: 2026-09-28
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Database Tampering via Arbitrary SQL
Action: Apply Patch
AI Analysis

Impact

SiYuan versions before 3.8.4 do not validate SQL statements embedded in block query blocks. An attacker can craft a malicious .sy document that contains non‑read‑only SQL and when the document is processed—during background indexing, rendering, or export—those statements are executed automatically, allowing the data in siyuan.db to be altered or deleted without authentication.

Affected Systems

SiYuan Note’s SiYuan editor, versions older than v3.8.4,

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact vulnerability, but the EPSS score is not available, suggesting limited publicly known exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to supply a malicious .sy file to the target system, which is then automatically processed by the application in the background, thus the attack vector is via document upload or file sharing. Successful exploitation could lead to unauthorized data modification or deletion.

Generated by OpenCVE AI on September 28, 2026 at 23:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SiYuan to version 3.8.4 or later to apply the vendor patch.
  • If an immediate upgrade is not possible, isolate untrusted .sy files by restricting their import location and disable automatic indexing or export until patched.
  • Validate all SQL statements in block query embed blocks before execution, rejecting any non‑read‑only statements to mitigate injection.
  • Monitor database logs for unexpected write operations and enforce least‑privilege access to siyuan.db.

Generated by OpenCVE AI on September 28, 2026 at 23:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db. Attackers can craft malicious .sy documents with non-read-only SQL statements that execute automatically during background indexing, rendering, or export operations without authentication.
Title SiYuan before v3.8.4 SQL Injection via Block Query Embed
First Time appeared B3log
B3log siyuan
Weaknesses CWE-89
CPEs cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*
Vendors & Products B3log
B3log siyuan
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-28T22:00:17.204Z

Reserved: 2026-09-27T20:29:07.433Z

Link: CVE-2026-101091

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-28T22:17:30.413

Modified: 2026-09-28T22:17:30.550

Link: CVE-2026-101091

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T23:30:09Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')