CVE-2026-72807: SiYuan: second-order SQLi via malicious template packages
GHSA-x67c-8pwr-m8g3 HIGH PoC AVAILABLESiYuan, a personal knowledge-management tool, contains a second-order SQL injection in its attribute-view template columns: the queryBlocks function builds raw SQL via string substitution instead of parameterized queries, so a crafted template column embedded in a shared document or package executes arbitrary SQL against the victim's kernel database once imported and rendered. The practical risk is bounded by CVSS 3.1's AC:H and UI:R — an attacker can't trigger this remotely without the victim actively importing a malicious file, and there's no public exploit, no Nuclei template, and no CISA KEV listing, which is consistent with CISA's own SSVC decision of TRACK (monitor, don't scramble) and an EPSS score of just 0.2%. Still, the impact if triggered is significant: confidentiality and integrity are both rated High under a changed scope, meaning the attacker's SQL can read and write across notebooks, not just the imported document, which matters if SiYuan is used as a local knowledge store feeding notes into AI workflows or shared as templates within a team. Upgrade to SiYuan v3.7.4 or later, and until patched treat any inbound SiYuan document, template, or package from outside your organization as untrusted content that should not be imported or rendered. Detection is limited to file-based controls — flag SiYuan package/template imports from external sources and monitor for anomalous kernel database writes if you operate SiYuan at scale.
What is the risk?
This is a high-severity (CVSS 8.0) second-order SQL injection, but the exploitation path requires social engineering (a user must be convinced to import a malicious document or package) and high attack complexity, which meaningfully limits scale. The EPSS score of 0.2% is low in absolute terms, though it still places the CVE in a relatively high percentile among all scored CVEs given how skewed the overall EPSS distribution is toward near-zero scores — this reflects relative, not imminent, exploitation likelihood. No public exploit code, no Nuclei scanning template, and no CISA KEV listing exist, and CISA's SSVC decision is TRACK, indicating monitoring rather than urgent action. The real risk driver is the changed scope (S:C) combined with High/High confidentiality and integrity impact: a single successful import compromises data across all notebooks in the kernel, not just the malicious document itself, which is a disproportionate blast radius for a UI-required bug and worth prioritizing in patch cycles even without active exploitation signals.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| Jupyter Notebook | go | < 0.0.0-20260723035036-0a176345e02a | 0.0.0-20260723035036-0a176345e02a |
Do you use Jupyter Notebook? You're affected.
How severe is it?
What is the attack surface?
What should I do?
1 step-
Upgrade SiYuan to v3.7.4 or later immediately, where queryBlocks presumably uses parameterized queries. Until patched, do not import SiYuan documents, template columns, or packages from untrusted or unknown sources — treat community-shared templates the same as untrusted executable content. Restrict package/template import capability to vetted internal sources if SiYuan is deployed in a team setting. For detection, audit recent imports for template columns containing SQL-like syntax or unexpected special characters, and monitor the SiYuan kernel's SQLite database file for unexpected schema or data changes following an import event. Reference the vendor advisory (GHSA-x67c-8pwr-m8g3) for the exact patched diff to confirm the fix covers all queryBlocks call sites.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-72807?
SiYuan, a personal knowledge-management tool, contains a second-order SQL injection in its attribute-view template columns: the queryBlocks function builds raw SQL via string substitution instead of parameterized queries, so a crafted template column embedded in a shared document or package executes arbitrary SQL against the victim's kernel database once imported and rendered. The practical risk is bounded by CVSS 3.1's AC:H and UI:R — an attacker can't trigger this remotely without the victim actively importing a malicious file, and there's no public exploit, no Nuclei template, and no CISA KEV listing, which is consistent with CISA's own SSVC decision of TRACK (monitor, don't scramble) and an EPSS score of just 0.2%. Still, the impact if triggered is significant: confidentiality and integrity are both rated High under a changed scope, meaning the attacker's SQL can read and write across notebooks, not just the imported document, which matters if SiYuan is used as a local knowledge store feeding notes into AI workflows or shared as templates within a team. Upgrade to SiYuan v3.7.4 or later, and until patched treat any inbound SiYuan document, template, or package from outside your organization as untrusted content that should not be imported or rendered. Detection is limited to file-based controls — flag SiYuan package/template imports from external sources and monitor for anomalous kernel database writes if you operate SiYuan at scale.
Is CVE-2026-72807 actively exploited?
Proof-of-concept exploit code is publicly available for CVE-2026-72807, increasing the risk of exploitation.
How to fix CVE-2026-72807?
Upgrade SiYuan to v3.7.4 or later immediately, where queryBlocks presumably uses parameterized queries. Until patched, do not import SiYuan documents, template columns, or packages from untrusted or unknown sources — treat community-shared templates the same as untrusted executable content. Restrict package/template import capability to vetted internal sources if SiYuan is deployed in a team setting. For detection, audit recent imports for template columns containing SQL-like syntax or unexpected special characters, and monitor the SiYuan kernel's SQLite database file for unexpected schema or data changes following an import event. Reference the vendor advisory (GHSA-x67c-8pwr-m8g3) for the exact patched diff to confirm the fix covers all queryBlocks call sites.
What systems are affected by CVE-2026-72807?
This vulnerability affects the following AI/ML architecture patterns: RAG pipelines.
What is the CVSS score for CVE-2026-72807?
CVE-2026-72807 has a CVSS v3.1 base score of 8.0 (HIGH). The EPSS exploitation probability is 0.33%.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0011 User Execution AML.T0011.001 Malicious Package AML.T0037 Data from Local System Compliance Controls Affected
What are the technical details?
Original Advisory
SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that expose the queryBlocks function, which executes raw SQL using string substitution instead of parameterized queries. Attackers can distribute malicious SiYuan documents or packages with crafted template columns that execute arbitrary SQL on a victim's kernel when the package is imported and rendered, enabling read and write access across notebooks.
Exploitation Scenario
An attacker crafts a SiYuan document or shareable package containing an attribute-view template column with a malicious payload embedded in a field the queryBlocks function later substitutes directly into a SQL string. The attacker distributes this package through a community template marketplace, forum, or direct file share, framing it as a useful productivity template (e.g., a project tracker or research notebook). A victim imports the package into their SiYuan instance and opens or renders the attribute view, at which point queryBlocks executes the attacker's injected SQL against the kernel's database with the application's own privileges — the 'second-order' nature means the payload lies dormant in stored data until the template is actually queried/rendered. The attacker can then read data from other notebooks (exfiltrating notes, credentials, or AI-context material stored in SiYuan) or write/corrupt data across the victim's entire knowledge base, potentially poisoning content that downstream AI workflows treat as trusted.
Weaknesses (CWE)
CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine
Primary
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Primary
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE-1336 — Improper Neutralization of Special Elements Used in a Template Engine: The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.
- [Architecture and Design] Choose a template engine that offers a sandbox or restricted mode, or at least limits the power of any available expressions, function calls, or commands.
- [Implementation] Use the template engine's sandbox or restricted mode, if available.
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N References
- github.com/siyuan-note/siyuan/security/advisories/GHSA-x67c-8pwr-m8g3
- vulncheck.com/advisories/siyuan-before-sql-injection-via-queryblocks-template
- github.com/advisories/GHSA-x67c-8pwr-m8g3
- github.com/siyuan-note/siyuan/commit/0a176345e02a0d19bdc7762e50e0b92002087d20
- nvd.nist.gov/vuln/detail/CVE-2026-72807
Timeline
Related Vulnerabilities
CVE-2026-72811 10.0 SiYuan: SQL injection enables cross-notebook DB access
Same package: notebook CVE-2026-69085 10.0 SiYuan: SQL injection in searchDocs allows DB tampering
Same package: notebook CVE-2026-69084 10.0 SiYuan: SQL injection in search endpoint exposes notebooks
Same package: notebook CVE-2026-69083 10.0 SiYuan: unauthenticated SQLi in full-text search endpoint
Same package: notebook CVE-2026-92938 9.9 Analysis pending
Same package: notebook