CyberRota Analysis
AI-GeneratedVersions of SiYuan up to v3.7.2 are vulnerable to a critical SQL injection flaw that allows attackers to execute arbitrary SQL commands through improperly sanitized user input in the backlink/mention search query. This vulnerability can be exploited by anonymous or low-privilege users, leading to unauthorized access and manipulation of data across notebooks. Organizations using affected versions should prioritize upgrading to v3.7.4 to mitigate the risk of data breaches and integrity issues.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and the client-supplied keyword into a SQL MATCH/search statement while escaping only the double-quote character and not the single quote. A single quote in the client keyword (first-order, reachable by an anonymous or RoleReader user on the publish surface) or in stored document metadata (second-order) breaks out of the string literal. Because the query runs on the main read-write siyuan.db handle via a statement-stacking-capable driver, an attacker can execute arbitrary SQL, enabling cross-notebook read and write. Fixed in v3.7.4.