Summary
CVE-2026-69084 is a critical SQL injection vulnerability in SiYuan Note (siyuan-note/siyuan) affecting all versions up to and including v3.7.2. The /api/search/searchEmbedBlock endpoint passes a client-supplied SQL statement directly to the main read-write database, allowing an unauthenticated or reader-role attacker to read and modify content across all cleartext notebooks. It is rated Critical (CVSS v3.1 10.0 / CVSS v4.0 9.9).
Technical details
- Root cause: The
POST /api/search/searchEmbedBlockendpoint accepts astmtparameter and passes it verbatim to the database viaSearchEmbedBlock → SearchEmbedBlockInBox → sql.SelectBlocksRawStmtNoParse(), with noCheckSingleStatement,CheckReadonlyStatement, orCheckAdminRoleguards (CWE-89). - Trigger conditions: Publish mode enabled with authentication disabled, or a request authenticated with a publish
RoleReadertoken. The statement executes against the global read-writesiyuan.dbhandle, which supports stacked,;-separated statements. - Attack vector: Network; remote and unauthenticated when publish authentication is disabled. No user interaction and no elevated privileges required.
- Impact: Arbitrary SQL read/write across all opened cleartext notebooks, enabling content disclosure and modification without admin credentials or write-API permissions. Encrypted notebooks remain protected.
Affected software
- SiYuan Note (siyuan-note/siyuan kernel) — all versions up to and including v3.7.2.
Severity
- CVSS v3.1 base score: 10.0 (Critical) — vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N. - CVSS v4.0 base score: 9.9 (Critical) — vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N.
Mitigation and recommended actions
- Immediate: Upgrade to SiYuan Note v3.7.3 or later, which adds statement validation to the affected endpoint.
- If no patch can be applied: Enable authentication on the publish server (do not run publish mode with authentication disabled), and restrict network access to the SiYuan instance so the
/api/search/searchEmbedBlockendpoint is not reachable by untrusted clients.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
Access Authorization - SiYuan,思源笔记 - Raw response body:
exitSiYuan,b3log.org/siyuan

