AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-72811

CRITICAL · CVSS 10 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Versions of SiYuan up to v3.7.2 are vulnerable to a critical SQL injection flaw that allows attackers to execute arbitrary SQL commands through improperly sanitized user input in the backlink/mention search query. This vulnerability can be exploited by anonymous or low-privilege users, leading to unauthorized access and manipulation of data across notebooks. Organizations using affected versions should prioritize upgrading to v3.7.4 to mitigate the risk of data breaches and integrity issues.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-72811
Severity
CRITICAL
CVSS
10
EPSS
N/A

Original NVD Description

SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and the client-supplied keyword into a SQL MATCH/search statement while escaping only the double-quote character and not the single quote. A single quote in the client keyword (first-order, reachable by an anonymous or RoleReader user on the publish surface) or in stored document metadata (second-order) breaks out of the string literal. Because the query runs on the main read-write siyuan.db handle via a statement-stacking-capable driver, an attacker can execute arbitrary SQL, enabling cross-notebook read and write. Fixed in v3.7.4.