high · CVSS v3 7.1 · CVSS v4 7.1
CVE-2026-101091
SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyu…
Description
SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db. Attackers can craft malicious .sy documents with non-read-only SQL statements that execute automatically during background indexing, rendering, or export operations without authentication.
Scores
- Severity
- high
- CVSS v2
- 8.5
- CVSS v3
- 7.1
- CVSS v4
- 7.1
- EPSS
- —