CVE-2026-72811
Description
SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and the client-supplied keyword into a SQL MATCH/search statement while escaping only the double-quote character and not the single quote. A single quote in the client keyword (first-order, reachable by an anonymous or RoleReader user on the publish surface) or in stored document metadata (second-order) breaks out of the string literal. Because the query runs on the main read-write siyuan.db handle via a statement-stacking-capable driver, an attacker can execute arbitrary SQL, enabling cross-notebook read and write. Fixed in v3.7.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/siyuan-note/siyuan/kernelGo | < 0.0.0-20260723004839-1a5b3431d5ab | 0.0.0-20260723004839-1a5b3431d5ab |
Affected products
2- Range: <=v3.7.2, fixed in v3.7.4
- ghsa-coordsRange: < 0.0.0-20260723004839-1a5b3431d5ab
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-q2vg-7qgx-x5fcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-72811ghsaADVISORY
- github.com/siyuan-note/siyuan/commit/1a5b3431d5ab3036b19c1cc79486fedd6906fb57ghsaWEB
- github.com/siyuan-note/siyuan/security/advisories/GHSA-q2vg-7qgx-x5fcnvdWEB
- www.vulncheck.com/advisories/siyuan-before-sql-injection-via-backlink-searchnvdWEB
News mentions
1- Siyuan Note: 25 Vulnerabilities Including RCE and Auth Bypass Disclosed TogetherVypr Intelligence · Aug 15, 2026