PatchSiren cyber security CVE debrief
CVE-2026-69085 siyuan-note CVE debrief
Unauthenticated SQL injection vulnerability in SiYuan's searchDocs endpoint allows read and write access across all non-encrypted notebooks. The endpoint concatenates user-supplied search keywords directly into SQL statements without proper escaping or parameter binding, allowing attackers to execute stacked SQL statements. This vulnerability affects SiYuan users, administrators, and security teams, who should assess exposure and prioritize remediation. The vulnerability has a CVSS score of 9.9 and is considered critical.
- Vendor
- siyuan-note
- Product
- github.com/siyuan-note/siyuan/kernel
- CVSS
- CRITICAL 9.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-01
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-01
- Advisory updated
- 2026-10-07
Who should care
SiYuan users, administrators, and security teams should assess exposure and prioritize remediation. They should verify their instances, restrict access to the endpoint, and update to the latest version. Security teams should review compensating controls for exposed systems and monitor for suspicious activity on the instance.
Why it matters
CVE-2026-69085 is a critical unauthenticated SQL injection vulnerability in SiYuan's searchDocs endpoint. It allows attackers to read and write database content across all cleartext notebooks on the instance. SiYuan users and administrators should verify their instances, restrict access to the endpoint, and update to the latest version.
- Potential unauthorized data access and modification across notebooks.
- Risk of data tampering and integrity loss.
- Possible lateral movement within the instance.
- Need for urgent verification and patching
Technical summary
The /api/filetree/searchDocs endpoint in SiYuan is vulnerable to unauthenticated SQL injection. The endpoint concatenates user-supplied search keywords directly into SQL statements without proper escaping or parameter binding. This allows attackers to execute stacked SQL statements, potentially leading to read and write access across all non-encrypted notebooks on the instance. The vulnerability exists in the kernel/api/filetree.go and kernel/model/file.go files, where the search keyword is passed directly to the SearchDocs function without sanitization.
Defensive priority
High priority for SiYuan users to verify and update their instances.
Recommended defensive actions
- Verify SiYuan instance configurations and update to the latest version.
- Restrict access to the searchDocs endpoint.
- Monitor for suspicious activity on the instance.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The vulnerability exists in the /api/filetree/searchDocs endpoint, which concatenates user-supplied search keywords directly into SQL statements without escaping or parameter binding. This allows unauthenticated requests to read and write database content across all cleartext notebooks on the instance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-69085 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-69085
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-69085 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-69085
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/Go/GHSA-33jq-p8c2-q3q4.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/siyuan-note/siyuan/security/advisories/GHSA-33jq-p8c2-q3q4
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/siyuan-note/siyuan
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/siyuan-note/siyuan/releases/tag/v3.7.3
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/siyuan-before-sql-injection-via-searchdocs
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.