Junglewise Threat Intelligence

SiYuan unauthenticated SQL injection in searchDocs via unescaped keyword

Severity: critical · CVSS 10 · Published 2026-10-01

Technologies: SiYuan, github.com/siyuan-note/siyuan/kernel (Go). Vendors: SiYuan, Go.

Executive brief

SiYuan is a note-taking application that stores documents in local SQLite databases. An unauthenticated attacker can inject arbitrary SQL into the search endpoint when publish mode is enabled without authentication, allowing them to read and modify all document content across unencrypted notebooks and potentially exfiltrate sensitive data or corrupt records.

Technical details

The `/api/filetree/searchDocs` endpoint concatenates user-supplied search keywords directly into SQL statements without escaping or parameter binding. The underlying SQLite driver executes stacked statements (separated by semicolons), and the database handle is opened in read-write mode. An unauthenticated request reaching this endpoint via publish mode can execute arbitrary SQL against the global blocks table spanning all non-encrypted notebooks, enabling both data disclosure and modification through statement stacking.

Affected products

  • SiYuan SiYuan <unknown, prior to patch

Timeline

  • 2026-10-01: disclosed: GHSA advisory published

Related threats