Junglewise Threat Intelligence

Duplicate Advisory: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw S

Severity: low · CVSS 3.1 · Published 2026-08-03

Technologies: github.com/siyuan-note/siyuan (Go). Vendors: Go.

Executive brief

Duplicate Advisory: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB

Affected products

  • Go github.com/siyuan-note/siyuan

Related threats