Impact
The vulnerability in SiYuan’s graph.go file allows an attacker to inject arbitrary SQL statements by inserting specially crafted HTML span tags into the getGraph endpoint. When these tags are processed, their attribute values are concatenated directly into a SQL query string without escaping single quotes, leading to a classic SQL injection flaw. This flaw can be exploited by anyone who can view a publish‑mode document or who can act as an anonymous visitor, enabling the attacker to read, modify, or delete data stored in the application’s read‑write database.
Affected Systems
All installations of Siyuan Notes running a version earlier than 3.8.3 are affected. The vendor product is Siyuan Note, and the affected component is the graph.go query2Stmt implementation used in the getGraph HTTP endpoint.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. EPSS < 1% indicates a very low exploitation probability, and the vulnerability is not yet in the CISA KEV catalog. The attack vector is inferred to be network‑based: an attacker can trigger the vulnerability by accessing the getGraph endpoint with a crafted request. Once triggered, the attacker can execute arbitrary SQL against the application database and exfiltrate sensitive data from multiple notebooks.
OpenCVE Enrichment