Executive brief
SiYuan is a note-taking application that supports read-only deployment mode for data protection. An incomplete security fix allows authenticated administrators to bypass the read-only restriction by submitting SQL queries through the global search endpoint, gaining direct database access that should be blocked. This undermines the security guarantees of read-only mode deployments.
Technical details
The vulnerability is an incomplete fix for CVE-2026-32767. The original patch added an administrator privilege check to the /api/search/fullTextSearchBlock endpoint's SQL mode (method=2), but failed to enforce the application's read-only boundary. When a workspace runs with --readonly=true, the dedicated /api/query/sql endpoint is correctly blocked by model.CheckReadonly, but /api/search/fullTextSearchBlock with method=2 bypasses this check by not calling CheckReadonly or CheckReadonlyStatementInBox before forwarding user-supplied SQL to the blocks database. An authenticated administrator can exploit this by sending crafted SQL queries to read arbitrary data from the blocks database in a read-only deployment. The fix in v3.8.2 adds the missing read-only boundary enforcement.
Affected products
- SiYuan SiYuan <=3.8.1
Timeline
- 2026-09-09: disclosed
- 2026-09-09: patched: Fixed in v3.8.2