rootpwn

high · CVSS v3 7.6 · CVSS v4 7.2

CVE-2026-93591

SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values…

Description

SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without escaping single quotes. A publish-mode reader or anonymous visitor can inject SQL via inline HTML span tags in the getGraph endpoint to execute arbitrary queries on the read-write database and exfiltrate private data across notebooks.

Scores

Severity
high
CVSS v2
8
CVSS v3
7.6
CVSS v4
7.2
EPSS

← All CVEs