Skip to content
CVE-2026-69083 - Exploits & Severity

CVE-2026-69083 - Exploits & Severity

Feedly August 3, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)

SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint of SiYuan versions before v3.7.3. Unescaped method parameters and REGEXP clauses in the read-write asset-content database allow arbitrary SQL execution.

Unauthenticated attackers over the network and users with publish RoleReader tokens can execute arbitrary SQL commands on the asset-content database to read, modify, or delete cross-notebook data.

One proof-of-concept exploit is available on github.com. There is no evidence of proof of exploitation at the moment.

Patch available. Upgrade to SiYuan v3.7.3 or later.

Upgrade SiYuan to version v3.7.3 or later immediately. Restrict network access to the fullTextSearchAssetContent endpoint if immediate patching is not possible. Review access logs for evidence of exploitation. Limit issuance of publish RoleReader tokens to trusted users only.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

NVD published the first details for CVE-2026-69083

Feedly found the first article mentioning CVE-2026-69083 . See article

GitHub Advisories released a security advisory .

A proof of concept exploit has been released

CVE Daily Brief — 2026-08-04

CVE-2026-69083: SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent [CRITICAL]

Critical SQL Injection Vulnerability Discovered in SiYuan Software

CVE-2026-69083 - Exploits & Severity - Feedly

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)