Summary
CVE-2026-59834 is a high-severity SQL injection vulnerability (CWE-89) in SiYuan, an open-source self-hosted personal knowledge management system. The flaw exists in the block search endpoint POST /api/search/fullTextSearchBlock, where user-supplied paths[] values are concatenated directly into SQL predicates, enabling an unauthenticated publish visitor to inject a UNION SELECT statement and exfiltrate content from documents that are hidden from public access. The issue is fixed in version 3.7.1, and all prior versions are affected.
Technical details
- Root cause: The
paths[]request parameter undergoes no SQL escaping before being concatenated viafmt.Sprintf()into WHERE clause predicates used by non-SQL search modes. This allows arbitrary SQL to be appended to the query. - Bypass mechanism: The injected
UNION SELECTprojects a visible notebook’sboxandpathvalues alongside rows from hidden documents. Because the publish access filter trusts theboxandpathfields returned from the SQL result set rather than enforcing visibility checks during query execution, the injected rows pass post-query validation undetected. - Attack vector: Any unauthenticated visitor of a SiYuan instance with the publish feature enabled receives a reader-role token, which is sufficient to send crafted requests to the vulnerable endpoint. No additional credentials or privileges are required.
- Impact: Successful exploitation allows an unauthenticated attacker to read block-level content from documents that SiYuan’s visibility controls are designed to keep hidden, resulting in a complete bypass of the publish access model and unauthorized disclosure of private knowledge base content.
Affected software
- SiYuan (siyuan-note/siyuan) — all versions prior to 3.7.1
Severity
CVSS v3.1 Base Score: 7.5 (HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Upgrade SiYuan to version 3.7.1 or later, which replaces string concatenation with parameterized SQL queries and enforces visibility filters at query execution time rather than post-query.
- If immediate patching is not possible: Restrict public network access to the SiYuan instance (e.g., place it behind a VPN or firewall) and disable the publish feature until the upgrade can be applied.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

