Executive brief
SiYuan is a privacy-focused note-taking application that stores personal notebooks. A vulnerability in the graph feature allows a reader or public visitor to inject SQL commands through specially crafted HTML tags, enabling attackers to bypass access controls and steal private notes from other notebooks that the attacker shouldn't have permission to access.
Technical details
This is an SQL injection vulnerability in the query2Stmt function in graph.go where tag values parsed from inline HTML span elements are concatenated directly into SQL string literals without escaping single quotes. The vulnerability exists only in the tag-parsing branch (lines 708, 715); the keyword-parsing branch correctly applies quote escaping. An attacker with publish-mode reader access (or anonymous access when authentication is disabled) can send a POST request to /api/graph/getGraph with a malicious span tag containing a UNION SELECT payload to break out of the string literal. The injected SQL executes against the read-write database with full query capability, allowing extraction of arbitrary block and reference rows across all notebooks. The attack bypasses the post-query access filter (FilterGraphByPublishAccess) by projecting allowed box/path values while placing sensitive data in result columns that become node titles/labels. Patches are available in version 3.8.3 and later.
Affected products
- SiYuan SiYuan before 3.8.3
Timeline
- 2026-09-18: disclosed: CVE-2026-93591 and GHSA-5rwv-4j4c-f954 published
- 2026-09-04: patched: Fixed in v3.8.3