Back exploit-intel.com CVE-2026-69083: SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent [CRITICAL] Exploit Intelligence — CVEs with Exploits / 12h This exploit demonstrates an unauthenticated SQL injection vulnerability (CVE-2026-69083) in SiYuan < 3.7.3 via the `/api/search/fullTextSearchAssetContent` endpoint. SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated SQL injection vulnerability (CVE-2026-69083) in SiYuan < 3.7.3 via the `/api/ /fullTextSearchAssetContent` endpoint. The PoC exploits improper string concatenation in a REGEXP clause to dump the asset-content SQLite database, enabling data exfiltration.
SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Attackers can execute arbitrary SQL on the read-write asset-content database via unescaped method parameters and REGEXP clauses to read, modify, or delete cross-notebook data.
This exploit demonstrates an unauthenticated SQL injection vulnerability (CVE-2026-69083) in SiYuan < 3.7.3 via the `/api/ /fullTextSearchAssetContent` endpoint. The PoC exploits improper string concatenation in a REGEXP clause to dump the asset-content SQLite database, enabling data exfiltration.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
