SiYuan, the self-hosted knowledge-management tool, builds its backlink/mention search query by string concatenation and only escapes double quotes — leaving a textbook single-quote SQL injection reachable by anonymous or read-only users on the public sharing surface, and even via second-order payloads planted in shared document metadata. Because the query runs against the live, read-write siyuan.db connection over a driver that permits statement stacking, a successful injection isn't limited to reading data: an attacker can read and write across every notebook in the instance, the full-severity outcome reflected in the CVSS 10.0 score (C:H/I:H). There is no public exploit or scanner template yet and EPSS sits at just 0.0025 (still 83rd percentile — most scored CVEs are less likely to be exploited than this one), and it is not in CISA KEV, so this reads as high-severity-but-not-yet-weaponized rather than an active incident. Any team self-hosting SiYuan — especially instances with public sharing/publish enabled or any anonymous/RoleReader accounts — should upgrade to v3.7.4 immediately, since there is no viable workaround for raw string-concatenation SQLi. Until patched, disable public sharing/anonymous access to the backlink search surface and audit siyuan.db and stored document metadata for signs of already-planted injection payloads.
What is the risk?
CVSS 10.0 (AV:N/AC:L/PR:N/UI:N) reflects the worst-case combination for a self-hosted app: no authentication or user interaction required, low attack complexity, and a scope change with full confidentiality and integrity impact across the whole instance. The primary mitigating factor is exposure — exploitation requires either public sharing/publish mode enabled or an existing anonymous/RoleReader account, so private, non-shared deployments are not reachable pre-auth. EPSS (0.0025, 83rd percentile) and the absence of CISA KEV listing, public PoC, or Nuclei template indicate exploitation is plausible but not yet observed in the wild — treat this as high-urgency-to-patch rather than active-incident.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| Jupyter Notebook | go | < 0.0.0-20260723004839-1a5b3431d5ab | 0.0.0-20260723004839-1a5b3431d5ab |
| siyuan | — | — | No patch |
How severe is it?
What is the attack surface?
What should I do?
1 step-
Upgrade to SiYuan v3.7.4 or later immediately — this is the only complete fix since the root cause is unescaped single-quote concatenation in kernel/model/backlink.go. If immediate patching isn't possible, disable public sharing/publish mode and remove any anonymous or RoleReader accounts to eliminate the pre-auth attack surface. Audit existing notebooks for suspicious single-quote sequences in titles, names, aliases, or anchor text that may represent already-planted second-order payloads, and review siyuan.db for signs of unauthorized cross-notebook reads or writes. Going forward, monitor backlink/mention search requests for anomalous characters or stacked-statement patterns as a detection signal.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-72811?
SiYuan, the self-hosted knowledge-management tool, builds its backlink/mention search query by string concatenation and only escapes double quotes — leaving a textbook single-quote SQL injection reachable by anonymous or read-only users on the public sharing surface, and even via second-order payloads planted in shared document metadata. Because the query runs against the live, read-write siyuan.db connection over a driver that permits statement stacking, a successful injection isn't limited to reading data: an attacker can read and write across every notebook in the instance, the full-severity outcome reflected in the CVSS 10.0 score (C:H/I:H). There is no public exploit or scanner template yet and EPSS sits at just 0.0025 (still 83rd percentile — most scored CVEs are less likely to be exploited than this one), and it is not in CISA KEV, so this reads as high-severity-but-not-yet-weaponized rather than an active incident. Any team self-hosting SiYuan — especially instances with public sharing/publish enabled or any anonymous/RoleReader accounts — should upgrade to v3.7.4 immediately, since there is no viable workaround for raw string-concatenation SQLi. Until patched, disable public sharing/anonymous access to the backlink search surface and audit siyuan.db and stored document metadata for signs of already-planted injection payloads.
Is CVE-2026-72811 actively exploited?
No confirmed active exploitation of CVE-2026-72811 has been reported, but organizations should still patch proactively.
How to fix CVE-2026-72811?
Upgrade to SiYuan v3.7.4 or later immediately — this is the only complete fix since the root cause is unescaped single-quote concatenation in kernel/model/backlink.go. If immediate patching isn't possible, disable public sharing/publish mode and remove any anonymous or RoleReader accounts to eliminate the pre-auth attack surface. Audit existing notebooks for suspicious single-quote sequences in titles, names, aliases, or anchor text that may represent already-planted second-order payloads, and review siyuan.db for signs of unauthorized cross-notebook reads or writes. Going forward, monitor backlink/mention search requests for anomalous characters or stacked-statement patterns as a detection signal.
What systems are affected by CVE-2026-72811?
This vulnerability affects the following AI/ML architecture patterns: RAG pipelines (document source repositories), self-hosted knowledge management platforms, AI agent tool backends.
What is the CVSS score for CVE-2026-72811?
CVE-2026-72811 has a CVSS v3.1 base score of 10.0 (CRITICAL). The EPSS exploitation probability is 0.44%.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0025 Exfiltration via Cyber Means AML.T0036 Data from Information Repositories AML.T0049 Exploit Public-Facing Application Compliance Controls Affected
What are the technical details?
Original Advisory
SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and the client-supplied keyword into a SQL MATCH/search statement while escaping only the double-quote character and not the single quote. A single quote in the client keyword (first-order, reachable by an anonymous or RoleReader user on the publish surface) or in stored document metadata (second-order) breaks out of the string literal. Because the query runs on the main read-write siyuan.db handle via a statement-stacking-capable driver, an attacker can execute arbitrary SQL, enabling cross-notebook read and write. Fixed in v3.7.4.
Exploitation Scenario
An attacker finds a SiYuan instance with public document sharing enabled (or holds a low-privilege RoleReader account) and submits a backlink search keyword containing a single quote followed by a stacked SQL statement, breaking out of the intended string literal in the MATCH/search query. Because the connection executes on the live read-write database and the driver permits multiple statements per call, the injected SQL runs immediately — for example, dumping the contents of a private notebook containing internal AI research notes, or writing a malicious block into another notebook. Alternatively, the attacker skips direct injection and instead plants a crafted single-quote payload inside a document's title or alias field; the next time any user, including a privileged one, performs a backlink search that touches that document, the second-order injection fires under that user's session, extending the blast radius well beyond the original attacker's own access.
Weaknesses (CWE)
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Primary
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'): The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
- [Architecture and Design] Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. For example, consider using persistence layers such as Hibernate or Enterprise Java Beans, which can provide significant protection against SQL injection if used properly.
- [Architecture and Design] If available, use structured mechanisms that automatically enforce the separation between data and code. These mechanisms may be able to provide the relevant quoting, encoding, and validation automatically, instead of relying on the developer to provide this capability at every point where output is generated. Process SQL queries using prepared statements, parameterized queries, or stored procedures. These features should accept parameters or variables and support strong typing. Do not dynamically construct and execute query strings within these features using "exec" or similar functionality, since this may re-introduce the possibility of SQL injection. [REF-867]
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N References
- github.com/siyuan-note/siyuan/security/advisories/GHSA-q2vg-7qgx-x5fc vendor-advisory
- vulncheck.com/advisories/siyuan-before-sql-injection-via-backlink-search third-party-advisory
- github.com/advisories/GHSA-q2vg-7qgx-x5fc
- github.com/siyuan-note/siyuan/commit/1a5b3431d5ab3036b19c1cc79486fedd6906fb57
- nvd.nist.gov/vuln/detail/CVE-2026-72811
Timeline
Related Vulnerabilities
CVE-2026-69084 10.0 SiYuan: SQL injection in search endpoint exposes notebooks
Same package: notebook CVE-2026-69083 10.0 SiYuan: unauthenticated SQLi in full-text search endpoint
Same package: notebook CVE-2026-44727 9.0 jupyter-server: stored XSS yields kernel RCE
Same package: notebook CVE-2026-52798 8.9 Gogs: Stored XSS via .ipynb Markdown re-render bypass
Same package: notebook CVE-2026-42557 8.8 JupyterLab: one-click RCE via notebook HTML cell output
Same package: notebook