{"id":"CVE-2026-59834","aliases":["GHSA-h89q-4j2h-7h88"],"url":"https://o3.security/vulnerability/CVE-2026-59834","summary":"SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content","details":"SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST /api/search/fullTextSearchBlock concatenates attacker-controlled paths values into SQL predicates used by non-SQL search modes, allowing an unauthenticated publish visitor to inject a UNION SELECT and return rows from hidden documents by projecting an allowed visible box and path. This issue is fixed in versions 3.7.1.","published":"2026-07-09T22:15:48.674Z","modified":"2026-08-12T03:51:21.101340400Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/siyuan-note/siyuan/kernel","fixedVersion":"0.0.0-20260704035518-d0f0fe146fb0"}],"fix":{"url":"https://github.com/siyuan-note/siyuan/commit/57bcad4b331836880bfe6be25d4180bdcf10db0d","label":"siyuan-note/siyuan@57bcad4"},"references":[{"type":"WEB","url":"https://github.com/siyuan-note/siyuan/releases/tag/v3.7.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59834.json"},{"type":"ADVISORY","url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-h89q-4j2h-7h88"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59834"},{"type":"FIX","url":"https://github.com/siyuan-note/siyuan/commit/57bcad4b331836880bfe6be25d4180bdcf10db0d"},{"type":"FIX","url":"https://github.com/siyuan-note/siyuan/commit/d0f0fe146fb07d594fcadc4f48d4f7c30ac01d1e"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:21.101340400Z"}}