Impact
SiYuan versions before 3.8.4 do not validate SQL statements embedded in block query blocks. An attacker can craft a malicious .sy document that contains non‑read‑only SQL and when the document is processed—during background indexing, rendering, or export—those statements are executed automatically, allowing the data in siyuan.db to be altered or deleted without authentication.
Affected Systems
SiYuan Note’s SiYuan editor, versions older than v3.8.4,
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact vulnerability, but the EPSS score is not available, suggesting limited publicly known exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to supply a malicious .sy file to the target system, which is then automatically processed by the application in the background, thus the attack vector is via document upload or file sharing. Successful exploitation could lead to unauthorized data modification or deletion.
OpenCVE Enrichment