Junglewise Threat Intelligence

CVE-2026-100644: SiYuan SQL injection in graph query endpoint

CVE-2026-100644 · Severity: high · CVSS 7.5 · Published 2026-09-26

Technologies: SiYuan Note SiYuan. Vendors: SiYuan Note.

Executive brief

SiYuan is a note-taking and knowledge management application that syncs across devices. Versions before 3.8.4 contain a SQL injection vulnerability in the graph query API that allows unauthenticated attackers to extract sensitive data from all notebooks when the application is published with authentication disabled. An attacker can read database contents including private notes and documents from other notebooks without any credentials.

Technical details

The vulnerability exists in the graphDailyNoteFilter() function in kernel/model/graph.go, where the dailyNoteSavePath parameter is concatenated directly into SQL queries without escaping. An attacker can close the SQL string literal with a quote and append arbitrary SQL (e.g., UNION SELECT) to extract rows from the workspace database. The attack requires the application to be published with authentication disabled; the unauthenticated requests are admitted as anonymous RoleReader under publish mode without credentials.

Affected products

  • siyuan-note SiYuan before 3.8.4

Timeline

  • 2026-09-26: disclosed
  • 2026-09-08: patched: v3.8.4 released with fix

References

Related threats