CyberRota Analysis
AI-GeneratedVersions of SiYuan prior to v3.8.4 are vulnerable due to improper validation of SQL statements in block query embed blocks, allowing attackers to create malicious .sy documents that execute unauthorized SQL commands during background processes. This could lead to unauthorized data access or manipulation without requiring authentication. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db. Attackers can craft malicious .sy documents with non-read-only SQL statements that execute automatically during background indexing, rendering, or export operations without authentication.