# CVE-2026-69085: SiYuan - SQLi

> Live exploitation tracking for CVE-2026-69085 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-69085

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **CVSS score:** 9.9
- **Public exploit available:** Yes
- **Affected products:** SiYuan
- **Weaknesses:** CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))
- **Tags:** web_application

## Description

SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no escaping or parameter binding. The endpoint is reachable by a publish RoleReader token, or unauthenticated when publish mode is enabled with Publish.Auth.Enable set to false. Because the statement executes on a read-write SQLite handle via a driver that supports stacked (semicolon-separated) statements, an attacker can read and modify database content across all cleartext (non-encrypted) notebooks on the instance.

## CrowdSec analysis

[CVE-2026-69085](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-69085) is a critical SQL injection vulnerability in SiYuan before v3.7.3, affecting the `/api/filetree/searchDocs` endpoint. Attackers can exploit an insufficiently sanitized keyword parameter with a publish RoleReader token, or without authentication when publish authentication is disabled, to execute stacked SQL statements. Successful exploitation may allow sensitive data disclosure and unauthorized modification of content across cleartext notebooks.

CrowdSec has been tracking this vulnerability and its exploits since 5th of October 2026.

CrowdSec has not observed any significant exploitation activity targeting CVE-2026-69085 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.

Attackers target the `/api/filetree/searchDocs` endpoint with a JSON `k` parameter containing SQLite UNION-based SQL injection syntax, often preceded by `/api/notebook/lsNotebooks` to obtain a valid notebook ID. Successful exploitation can expose or modify database content.

## Timeline

- 2026-08-03: CVE Published. CVE-2026-69085 is published to NVD.
- 2026-10-05: Rule Released. CrowdSec releases a rule to detect CVE-2026-69085 exploitation attempts against the CrowdSec Network.

## References

- https://github.com/siyuan-note/siyuan/security/advisories/GHSA-33jq-p8c2-q3q4
- https://www.vulncheck.com/advisories/siyuan-before-sql-injection-via-searchdocs
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-69085.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-69085) follows observed exploitation activity for CVE-2026-69085. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
