Junglewise Threat Intelligence

CVE-2026-87808: SiYuan read-only boundary bypass in fullTextSearchBlock SQL mode

CVE-2026-87808 · Severity: medium · CVSS 4.9 · Published 2026-09-09

Technologies: SiYuan. Vendors: SiYuan.

Executive brief

SiYuan is a note-taking application that supports read-only deployment mode for data protection. An incomplete security fix allows authenticated administrators to bypass the read-only restriction by submitting SQL queries through the global search endpoint, gaining direct database access that should be blocked. This undermines the security guarantees of read-only mode deployments.

Technical details

The vulnerability is an incomplete fix for CVE-2026-32767. The original patch added an administrator privilege check to the /api/search/fullTextSearchBlock endpoint's SQL mode (method=2), but failed to enforce the application's read-only boundary. When a workspace runs with --readonly=true, the dedicated /api/query/sql endpoint is correctly blocked by model.CheckReadonly, but /api/search/fullTextSearchBlock with method=2 bypasses this check by not calling CheckReadonly or CheckReadonlyStatementInBox before forwarding user-supplied SQL to the blocks database. An authenticated administrator can exploit this by sending crafted SQL queries to read arbitrary data from the blocks database in a read-only deployment. The fix in v3.8.2 adds the missing read-only boundary enforcement.

Affected products

  • SiYuan SiYuan <=3.8.1

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Fixed in v3.8.2

References

Related threats