CrowdSecLive Exploit Tracker
Limited ExploitationCVE-2026-69085Public Exploit

SiYuan - SQLi (CVE-2026-69085)

PublishedAug 3, 2026
First SeenN/A
Last Seen
Reported
CVSS9.9
web_application

Description

SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no escaping or parameter binding. The endpoint is reachable by a publish RoleReader token, or unauthenticated when publish mode is enabled with Publish.Auth.Enable set to false. Because the statement executes on a read-write SQLite handle via a driver that supports stacked (semicolon-separated) statements, an attacker can read and modify database content across all cleartext (non-encrypted) notebooks on the instance.

psychologyCrowdSec Analysis

CVE-2026-69085 is a critical SQL injection vulnerability in SiYuan before v3.7.3, affecting the /api/filetree/searchDocs endpoint. Attackers can exploit an insufficiently sanitized keyword parameter with a publish RoleReader token, or without authentication when publish authentication is disabled, to execute stacked SQL statements. Successful exploitation may allow sensitive data disclosure and unauthorized modification of content across cleartext notebooks.

CrowdSec has been tracking this vulnerability and its exploits since 5th of October 2026.

CrowdSec has not observed any significant exploitation activity targeting CVE-2026-69085 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.

Attackers target the /api/filetree/searchDocs endpoint with a JSON k parameter containing SQLite UNION-based SQL injection syntax, often preceded by /api/notebook/lsNotebooks to obtain a valid notebook ID. Successful exploitation can expose or modify database content.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2026-08-03
Rule Released2026-10-05

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.