HIGH 7.5 GitHub
CVE-2026-59834
SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content
## Summary
Siyuan's block search endpoint concatenates attacker-controlled `paths[]` values into SQL predicates used by non-SQL search modes. Through Siyuan's publish service, an unauthenticated visitor is forwarded to the kernel with a reader-role token and can reach `POST /api/search/fullTextSearchBlock`.
An attacker can inject a `UNION SELECT` through `paths[]` and return rows from hidden documents while projecting an allowed visible `box` and `path`. The post-query publish access filter tr
Affected Products
- go/github.com/siyuan-note/siyuan/kernel < 0.0.0-20260704035518-d0f0fe146fb0
References
- https://github.com/advisories/GHSA-h89q-4j2h-7h88
- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-h89q-4j2h-7h88
- https://nvd.nist.gov/vuln/detail/CVE-2026-59834
- https://github.com/siyuan-note/siyuan/commit/57bcad4b331836880bfe6be25d4180bdcf10db0d
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-09-02 via GitHub. Affected: go/github.com/siyuan-note/siyuan/kernel < 0.0.0-20260704035518-d0f0fe146fb0.
vulnfeed aggregates 11639 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.