CVE-2026-72811: SiYuan: SQL injection enables cross-notebook DB access

GHSA-q2vg-7qgx-x5fc CRITICAL
Published August 14, 2026
CISO Take

SiYuan, the self-hosted knowledge-management tool, builds its backlink/mention search query by string concatenation and only escapes double quotes — leaving a textbook single-quote SQL injection reachable by anonymous or read-only users on the public sharing surface, and even via second-order payloads planted in shared document metadata. Because the query runs against the live, read-write siyuan.db connection over a driver that permits statement stacking, a successful injection isn't limited to reading data: an attacker can read and write across every notebook in the instance, the full-severity outcome reflected in the CVSS 10.0 score (C:H/I:H). There is no public exploit or scanner template yet and EPSS sits at just 0.0025 (still 83rd percentile — most scored CVEs are less likely to be exploited than this one), and it is not in CISA KEV, so this reads as high-severity-but-not-yet-weaponized rather than an active incident. Any team self-hosting SiYuan — especially instances with public sharing/publish enabled or any anonymous/RoleReader accounts — should upgrade to v3.7.4 immediately, since there is no viable workaround for raw string-concatenation SQLi. Until patched, disable public sharing/anonymous access to the backlink search surface and audit siyuan.db and stored document metadata for signs of already-planted injection payloads.

Sources: NVD EPSS GitHub Advisory ATLAS

What is the risk?

CVSS 10.0 (AV:N/AC:L/PR:N/UI:N) reflects the worst-case combination for a self-hosted app: no authentication or user interaction required, low attack complexity, and a scope change with full confidentiality and integrity impact across the whole instance. The primary mitigating factor is exposure — exploitation requires either public sharing/publish mode enabled or an existing anonymous/RoleReader account, so private, non-shared deployments are not reachable pre-auth. EPSS (0.0025, 83rd percentile) and the absence of CISA KEV listing, public PoC, or Nuclei template indicate exploitation is plausible but not yet observed in the wild — treat this as high-urgency-to-patch rather than active-incident.

How does the attack unfold?

Reconnaissance / Access
Attacker identifies a publicly exposed SiYuan instance with the publish/sharing feature enabled or gains an anonymous/RoleReader account.
AML.T0049
Injection
Attacker submits a single-quote SQL payload as a backlink search keyword (first-order) or embeds it in a document's title, alias, or anchor text (second-order).
Execution
The unescaped single quote breaks out of the string literal, and the statement-stacking-capable driver executes the attacker's injected SQL against the live read-write siyuan.db.
AML.T0036
Impact
Attacker reads and writes across every notebook in the instance, exfiltrating private documents and/or planting malicious content instance-wide.
AML.T0025

What systems are affected?

Package Ecosystem Vulnerable Range Patched
Jupyter Notebook go < 0.0.0-20260723004839-1a5b3431d5ab 0.0.0-20260723004839-1a5b3431d5ab
13.4K OpenSSF 5.8 3.0K dependents Pushed 5d ago 83% patched ~106d to patch Full package profile →
siyuan — — No patch

How severe is it?

CVSS 3.1
10.0 / 10
EPSS
0.4%
chance of exploitation in 30 days
Higher than 35% of all CVEs
Exploitation Status
No known exploitation
Sophistication
Trivial

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC Low
PR None
UI None
S Changed
C High
I High
A None

What should I do?

1 step
  1. Upgrade to SiYuan v3.7.4 or later immediately — this is the only complete fix since the root cause is unescaped single-quote concatenation in kernel/model/backlink.go. If immediate patching isn't possible, disable public sharing/publish mode and remove any anonymous or RoleReader accounts to eliminate the pre-auth attack surface. Audit existing notebooks for suspicious single-quote sequences in titles, names, aliases, or anchor text that may represent already-planted second-order payloads, and review siyuan.db for signs of unauthorized cross-notebook reads or writes. Going forward, monitor backlink/mention search requests for anomalous characters or stacked-statement patterns as a detection signal.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

EU AI Act
Article 15 - Accuracy, robustness and cybersecurity
NIST AI RMF
MANAGE-4.1 - Mechanisms for managing AI system risks from third-party resources
OWASP LLM Top 10
LLM06 - Sensitive Information Disclosure

Frequently Asked Questions

What is CVE-2026-72811?

SiYuan, the self-hosted knowledge-management tool, builds its backlink/mention search query by string concatenation and only escapes double quotes — leaving a textbook single-quote SQL injection reachable by anonymous or read-only users on the public sharing surface, and even via second-order payloads planted in shared document metadata. Because the query runs against the live, read-write siyuan.db connection over a driver that permits statement stacking, a successful injection isn't limited to reading data: an attacker can read and write across every notebook in the instance, the full-severity outcome reflected in the CVSS 10.0 score (C:H/I:H). There is no public exploit or scanner template yet and EPSS sits at just 0.0025 (still 83rd percentile — most scored CVEs are less likely to be exploited than this one), and it is not in CISA KEV, so this reads as high-severity-but-not-yet-weaponized rather than an active incident. Any team self-hosting SiYuan — especially instances with public sharing/publish enabled or any anonymous/RoleReader accounts — should upgrade to v3.7.4 immediately, since there is no viable workaround for raw string-concatenation SQLi. Until patched, disable public sharing/anonymous access to the backlink search surface and audit siyuan.db and stored document metadata for signs of already-planted injection payloads.

Is CVE-2026-72811 actively exploited?

No confirmed active exploitation of CVE-2026-72811 has been reported, but organizations should still patch proactively.

How to fix CVE-2026-72811?

Upgrade to SiYuan v3.7.4 or later immediately — this is the only complete fix since the root cause is unescaped single-quote concatenation in kernel/model/backlink.go. If immediate patching isn't possible, disable public sharing/publish mode and remove any anonymous or RoleReader accounts to eliminate the pre-auth attack surface. Audit existing notebooks for suspicious single-quote sequences in titles, names, aliases, or anchor text that may represent already-planted second-order payloads, and review siyuan.db for signs of unauthorized cross-notebook reads or writes. Going forward, monitor backlink/mention search requests for anomalous characters or stacked-statement patterns as a detection signal.

What systems are affected by CVE-2026-72811?

This vulnerability affects the following AI/ML architecture patterns: RAG pipelines (document source repositories), self-hosted knowledge management platforms, AI agent tool backends.

What is the CVSS score for CVE-2026-72811?

CVE-2026-72811 has a CVSS v3.1 base score of 10.0 (CRITICAL). The EPSS exploitation probability is 0.44%.

What is the AI security impact?

Affected AI Architectures

RAG pipelines (document source repositories)self-hosted knowledge management platformsAI agent tool backends

MITRE ATLAS Techniques

AML.T0025 Exfiltration via Cyber Means
AML.T0036 Data from Information Repositories
AML.T0049 Exploit Public-Facing Application

Compliance Controls Affected

EU AI Act: Article 15
NIST AI RMF: MANAGE-4.1
OWASP LLM Top 10: LLM06

What are the technical details?

Original Advisory

SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and the client-supplied keyword into a SQL MATCH/search statement while escaping only the double-quote character and not the single quote. A single quote in the client keyword (first-order, reachable by an anonymous or RoleReader user on the publish surface) or in stored document metadata (second-order) breaks out of the string literal. Because the query runs on the main read-write siyuan.db handle via a statement-stacking-capable driver, an attacker can execute arbitrary SQL, enabling cross-notebook read and write. Fixed in v3.7.4.

Exploitation Scenario

An attacker finds a SiYuan instance with public document sharing enabled (or holds a low-privilege RoleReader account) and submits a backlink search keyword containing a single quote followed by a stacked SQL statement, breaking out of the intended string literal in the MATCH/search query. Because the connection executes on the live read-write database and the driver permits multiple statements per call, the injected SQL runs immediately — for example, dumping the contents of a private notebook containing internal AI research notes, or writing a malicious block into another notebook. Alternatively, the attacker skips direct injection and instead plants a crafted single-quote payload inside a document's title or alias field; the next time any user, including a privileged one, performs a backlink search that touches that document, the second-order injection fires under that user's session, extending the blast radius well beyond the original attacker's own access.

Weaknesses (CWE)

CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'): The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

  • [Architecture and Design] Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. For example, consider using persistence layers such as Hibernate or Enterprise Java Beans, which can provide significant protection against SQL injection if used properly.
  • [Architecture and Design] If available, use structured mechanisms that automatically enforce the separation between data and code. These mechanisms may be able to provide the relevant quoting, encoding, and validation automatically, instead of relying on the developer to provide this capability at every point where output is generated. Process SQL queries using prepared statements, parameterized queries, or stored procedures. These features should accept parameters or variables and support strong typing. Do not dynamically construct and execute query strings within these features using "exec" or similar functionality, since this may re-introduce the possibility of SQL injection. [REF-867]

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Timeline

Published
August 14, 2026
Last Modified
September 3, 2026
First Seen
August 14, 2026

Related Vulnerabilities