Junglewise Threat Intelligence

CVE-2026-101091: SiYuan block query embed SQL injection in background indexing

CVE-2026-101091 · Severity: high · CVSS 7.1 · Published 2026-09-28

Technologies: SiYuan. Vendors: SiYuan.

Executive brief

SiYuan is a note-taking application that stores documents with embedded SQL queries for dynamic content. Versions before 3.8.4 execute these SQL queries without proper validation during background indexing, rendering, and export operations. An attacker can craft a malicious document that, when opened or synced by a victim, automatically executes arbitrary database commands to exfiltrate or corrupt the user's notes without authentication.

Technical details

The vulnerability is an SQL injection in block query embed blocks executed against siyuan.db. The interactive search API enforces single-statement and read-only validation, but background auto-indexing, rendering, export, and asset paths execute the stored SQL directly through SelectBlocksRawStmt/SelectBlocksRawStmtNoParse without these guards. The auto-indexer only checks for a "select" substring, easily bypassed with SQL comments or subqueries. An unauthenticated attacker can deliver a crafted .sy document whose embedded SQL (e.g., VACUUM INTO or DELETE) executes automatically during indexing or rendering, copying or corrupting the victim's database.

Affected products

  • SiYuan SiYuan before 3.8.4

Timeline

  • 2026-09-28: disclosed: CVE-2026-101091 published on NVD
  • 2026-09-14: patched: Fix committed to repository; v3.8.4 released with guards on all execution paths

References

Related threats