CVE-2026-72807: SiYuan: second-order SQLi via malicious template packages

GHSA-x67c-8pwr-m8g3 HIGH PoC AVAILABLE
Published August 12, 2026
CISO Take

SiYuan, a personal knowledge-management tool, contains a second-order SQL injection in its attribute-view template columns: the queryBlocks function builds raw SQL via string substitution instead of parameterized queries, so a crafted template column embedded in a shared document or package executes arbitrary SQL against the victim's kernel database once imported and rendered. The practical risk is bounded by CVSS 3.1's AC:H and UI:R — an attacker can't trigger this remotely without the victim actively importing a malicious file, and there's no public exploit, no Nuclei template, and no CISA KEV listing, which is consistent with CISA's own SSVC decision of TRACK (monitor, don't scramble) and an EPSS score of just 0.2%. Still, the impact if triggered is significant: confidentiality and integrity are both rated High under a changed scope, meaning the attacker's SQL can read and write across notebooks, not just the imported document, which matters if SiYuan is used as a local knowledge store feeding notes into AI workflows or shared as templates within a team. Upgrade to SiYuan v3.7.4 or later, and until patched treat any inbound SiYuan document, template, or package from outside your organization as untrusted content that should not be imported or rendered. Detection is limited to file-based controls — flag SiYuan package/template imports from external sources and monitor for anomalous kernel database writes if you operate SiYuan at scale.

Sources: NVD EPSS GitHub Advisory ATLAS vulncheck.com

What is the risk?

This is a high-severity (CVSS 8.0) second-order SQL injection, but the exploitation path requires social engineering (a user must be convinced to import a malicious document or package) and high attack complexity, which meaningfully limits scale. The EPSS score of 0.2% is low in absolute terms, though it still places the CVE in a relatively high percentile among all scored CVEs given how skewed the overall EPSS distribution is toward near-zero scores — this reflects relative, not imminent, exploitation likelihood. No public exploit code, no Nuclei scanning template, and no CISA KEV listing exist, and CISA's SSVC decision is TRACK, indicating monitoring rather than urgent action. The real risk driver is the changed scope (S:C) combined with High/High confidentiality and integrity impact: a single successful import compromises data across all notebooks in the kernel, not just the malicious document itself, which is a disproportionate blast radius for a UI-required bug and worth prioritizing in patch cycles even without active exploitation signals.

How does the attack unfold?

Malicious package creation
Attacker crafts a SiYuan document or template package with a SQL injection payload embedded in an attribute-view template column.
AML.T0011.001
Distribution and import
The package is distributed via a template marketplace, forum, or direct share, and the victim imports it into their SiYuan kernel.
AML.T0011
Second-order SQL execution
When the template is later rendered or queried, queryBlocks substitutes the malicious string directly into SQL, executing it with kernel privileges.
AML.T0037
Cross-notebook read/write impact
The attacker gains read and write access across the victim's notebooks, enabling data theft or corruption of the knowledge base.

What systems are affected?

Package Ecosystem Vulnerable Range Patched
Jupyter Notebook go < 0.0.0-20260723035036-0a176345e02a 0.0.0-20260723035036-0a176345e02a
13.4K OpenSSF 5.8 3.0K dependents Pushed 9d ago 85% patched ~92d to patch Full package profile →

Do you use Jupyter Notebook? You're affected.

How severe is it?

CVSS 3.1
8.0 / 10
EPSS
0.3%
chance of exploitation in 30 days
Higher than 24% of all CVEs
Exploitation Status
Exploit Available
Exploitation: MEDIUM
Sophistication
Moderate
Exploitation Confidence
medium
○ Public PoC indexed (trickest/cve)
Composite signal derived from CISA KEV, VulnCheck KEV, CISA SSVC, EPSS, Metasploit, Exploit-DB, trickest/cve, Nuclei templates, and inthewild.io exploitation reports.

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC High
PR None
UI Required
S Changed
C High
I High
A None

What should I do?

1 step
  1. Upgrade SiYuan to v3.7.4 or later immediately, where queryBlocks presumably uses parameterized queries. Until patched, do not import SiYuan documents, template columns, or packages from untrusted or unknown sources — treat community-shared templates the same as untrusted executable content. Restrict package/template import capability to vetted internal sources if SiYuan is deployed in a team setting. For detection, audit recent imports for template columns containing SQL-like syntax or unexpected special characters, and monitor the SiYuan kernel's SQLite database file for unexpected schema or data changes following an import event. Reference the vendor advisory (GHSA-x67c-8pwr-m8g3) for the exact patched diff to confirm the fix covers all queryBlocks call sites.

What does CISA's SSVC say?

Decision Track
Exploitation none
Automatable No
Technical Impact total

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

ISO 42001
A.6.2 - Third-party and supplier relationships
NIST AI RMF
GOVERN 6.1 - Third-party risks and responsibilities
OWASP LLM Top 10
LLM03 - Supply Chain Vulnerabilities

Frequently Asked Questions

What is CVE-2026-72807?

SiYuan, a personal knowledge-management tool, contains a second-order SQL injection in its attribute-view template columns: the queryBlocks function builds raw SQL via string substitution instead of parameterized queries, so a crafted template column embedded in a shared document or package executes arbitrary SQL against the victim's kernel database once imported and rendered. The practical risk is bounded by CVSS 3.1's AC:H and UI:R — an attacker can't trigger this remotely without the victim actively importing a malicious file, and there's no public exploit, no Nuclei template, and no CISA KEV listing, which is consistent with CISA's own SSVC decision of TRACK (monitor, don't scramble) and an EPSS score of just 0.2%. Still, the impact if triggered is significant: confidentiality and integrity are both rated High under a changed scope, meaning the attacker's SQL can read and write across notebooks, not just the imported document, which matters if SiYuan is used as a local knowledge store feeding notes into AI workflows or shared as templates within a team. Upgrade to SiYuan v3.7.4 or later, and until patched treat any inbound SiYuan document, template, or package from outside your organization as untrusted content that should not be imported or rendered. Detection is limited to file-based controls — flag SiYuan package/template imports from external sources and monitor for anomalous kernel database writes if you operate SiYuan at scale.

Is CVE-2026-72807 actively exploited?

Proof-of-concept exploit code is publicly available for CVE-2026-72807, increasing the risk of exploitation.

How to fix CVE-2026-72807?

Upgrade SiYuan to v3.7.4 or later immediately, where queryBlocks presumably uses parameterized queries. Until patched, do not import SiYuan documents, template columns, or packages from untrusted or unknown sources — treat community-shared templates the same as untrusted executable content. Restrict package/template import capability to vetted internal sources if SiYuan is deployed in a team setting. For detection, audit recent imports for template columns containing SQL-like syntax or unexpected special characters, and monitor the SiYuan kernel's SQLite database file for unexpected schema or data changes following an import event. Reference the vendor advisory (GHSA-x67c-8pwr-m8g3) for the exact patched diff to confirm the fix covers all queryBlocks call sites.

What systems are affected by CVE-2026-72807?

This vulnerability affects the following AI/ML architecture patterns: RAG pipelines.

What is the CVSS score for CVE-2026-72807?

CVE-2026-72807 has a CVSS v3.1 base score of 8.0 (HIGH). The EPSS exploitation probability is 0.33%.

What is the AI security impact?

Affected AI Architectures

RAG pipelines

MITRE ATLAS Techniques

AML.T0011 User Execution
AML.T0011.001 Malicious Package
AML.T0037 Data from Local System

Compliance Controls Affected

ISO 42001: A.6.2
NIST AI RMF: GOVERN 6.1
OWASP LLM Top 10: LLM03

What are the technical details?

Original Advisory

SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that expose the queryBlocks function, which executes raw SQL using string substitution instead of parameterized queries. Attackers can distribute malicious SiYuan documents or packages with crafted template columns that execute arbitrary SQL on a victim's kernel when the package is imported and rendered, enabling read and write access across notebooks.

Exploitation Scenario

An attacker crafts a SiYuan document or shareable package containing an attribute-view template column with a malicious payload embedded in a field the queryBlocks function later substitutes directly into a SQL string. The attacker distributes this package through a community template marketplace, forum, or direct file share, framing it as a useful productivity template (e.g., a project tracker or research notebook). A victim imports the package into their SiYuan instance and opens or renders the attribute view, at which point queryBlocks executes the attacker's injected SQL against the kernel's database with the application's own privileges — the 'second-order' nature means the payload lies dormant in stored data until the template is actually queried/rendered. The attacker can then read data from other notebooks (exfiltrating notes, credentials, or AI-context material stored in SiYuan) or write/corrupt data across the victim's entire knowledge base, potentially poisoning content that downstream AI workflows treat as trusted.

Weaknesses (CWE)

CWE-1336 — Improper Neutralization of Special Elements Used in a Template Engine: The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.

  • [Architecture and Design] Choose a template engine that offers a sandbox or restricted mode, or at least limits the power of any available expressions, function calls, or commands.
  • [Implementation] Use the template engine's sandbox or restricted mode, if available.

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

Timeline

Published
August 12, 2026
Last Modified
September 3, 2026
First Seen
August 12, 2026

Related Vulnerabilities