Description
SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without escaping single quotes. A publish-mode reader or anonymous visitor can inject SQL via inline HTML span tags in the getGraph endpoint to execute arbitrary queries on the read-write database and exfiltrate private data across notebooks.
Published: 2026-09-18
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: High-Impact SQL Injection
Action: Patch Now
AI Analysis

Impact

The vulnerability in SiYuan’s graph.go file allows an attacker to inject arbitrary SQL statements by inserting specially crafted HTML span tags into the getGraph endpoint. When these tags are processed, their attribute values are concatenated directly into a SQL query string without escaping single quotes, leading to a classic SQL injection flaw. This flaw can be exploited by anyone who can view a publish‑mode document or who can act as an anonymous visitor, enabling the attacker to read, modify, or delete data stored in the application’s read‑write database.

Affected Systems

All installations of Siyuan Notes running a version earlier than 3.8.3 are affected. The vendor product is Siyuan Note, and the affected component is the graph.go query2Stmt implementation used in the getGraph HTTP endpoint.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity. EPSS < 1% indicates a very low exploitation probability, and the vulnerability is not yet in the CISA KEV catalog. The attack vector is inferred to be network‑based: an attacker can trigger the vulnerability by accessing the getGraph endpoint with a crafted request. Once triggered, the attacker can execute arbitrary SQL against the application database and exfiltrate sensitive data from multiple notebooks.

Generated by OpenCVE AI on September 19, 2026 at 18:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade SiYuan to version 3.8.3 or later to apply the vendor patch that properly escapes tag values.
  • Restrict or remove publish‑mode access for anonymous visitors or enforce authentication and authorization checks on the getGraph endpoint to limit who can request graph data.
  • Implement input sanitization on tag values or use parameterized queries to prevent any future injection attempts against the database.

Generated by OpenCVE AI on September 19, 2026 at 18:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without escaping single quotes. A publish-mode reader or anonymous visitor can inject SQL via inline HTML span tags in the getGraph endpoint to execute arbitrary queries on the read-write database and exfiltrate private data across notebooks.
Title SiYuan before 3.8.3 SQL Injection via unescaped tag in graph.go
First Time appeared B3log
B3log siyuan
Weaknesses CWE-89
CPEs cpe:2.3:a:b3log:siyuan:*:*:*:*:*:*:*:*
Vendors & Products B3log
B3log siyuan
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T19:55:54.946Z

Reserved: 2026-09-18T10:59:45.138Z

Link: CVE-2026-93591

cve-icon Vulnrichment

Updated: 2026-09-18T19:55:48.703Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T14:19:10.097

Modified: 2026-09-18T20:17:33.037

Link: CVE-2026-93591

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:00:15Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')