HIGH 7.5 GitHub

CVE-2026-59834

SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content

## Summary Siyuan's block search endpoint concatenates attacker-controlled `paths[]` values into SQL predicates used by non-SQL search modes. Through Siyuan's publish service, an unauthenticated visitor is forwarded to the kernel with a reader-role token and can reach `POST /api/search/fullTextSearchBlock`. An attacker can inject a `UNION SELECT` through `paths[]` and return rows from hidden documents while projecting an allowed visible `box` and `path`. The post-query publish access filter tr

Affected Products

References

Published: 2026-09-02 · Source: GitHub · Feed updated: 2026-09-02
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-09-02 via GitHub. Affected: go/github.com/siyuan-note/siyuan/kernel < 0.0.0-20260704035518-d0f0fe146fb0.
vulnfeed aggregates 11639 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.