{"id":"CVE-2026-69083","aliases":["GHSA-fph3-ghq9-vw66","GO-2026-6374"],"url":"https://o3.security/vulnerability/CVE-2026-69083","summary":"SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent","details":"SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Attackers can execute arbitrary SQL on the read-write asset-content database via unescaped method parameters and REGEXP clauses to read, modify, or delete cross-notebook data.","published":"2026-08-03T13:20:39.264Z","modified":"2026-09-10T15:25:36.094529025Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/siyuan-note/siyuan/kernel","fixedVersion":"0.0.0-20260721004815-cf42dd5680c8"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/69xxx/CVE-2026-69083.json"},{"type":"ADVISORY","url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-fph3-ghq9-vw66"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69083"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/siyuan-before-sql-injection-via-fulltextsearchassetcontent"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T15:25:36.094529025Z"}}