rootpwn

high · CVSS v3 7.1 · CVSS v4 7.1

CVE-2026-101091

SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyu…

Description

SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db. Attackers can craft malicious .sy documents with non-read-only SQL statements that execute automatically during background indexing, rendering, or export operations without authentication.

Scores

Severity
high
CVSS v2
8.5
CVSS v3
7.1
CVSS v4
7.1
EPSS
—

← All CVEs